ZeroHour

gunra

ransomware group · aka Gunra · unknown · active since 2025-04

Victims · 7d
0flat
Victims · 30d
1active targets
Victims · 90d
10
All-time (tracked)
53since 2025-04-23
Last post
08-19 16:24UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

Gunra is a double-extortion ransomware group first documented in April 2025, notable for posting large batches of new victims on its leak site in rapid succession. Vendor research in 2025 linked the group to breaches of exposed Fortinet FortiOS and FortiProxy edge devices via the actively exploited authentication-bypass flaws CVE-2024-55591 and CVE-2025-24472, with targets including critical-infrastructure and manufacturing organizations. Subsequent vendor reporting in 2025 described a Linux/ESXi encryptor variant in addition to its Windows tooling. The group maintains a global victim base, with recent leak-site listings on this dashboard spanning Latin America, Europe, and Asia (e.g., Mexico, Spain, Brazil, Thailand, Indonesia). It remained active through at least August 2026, though the 13 leak-site victims in the past 90 days on this dashboard suggest a slower cadence than the mass-posting observed at emergence.

Tactics & tooling
  • Initial access via exploitation of exposed Fortinet FortiOS/FortiProxy devices using authentication-bypass flaws CVE-2024-55591 and CVE-2025-24472 (vendor research, 2025)
  • Double extortion: file encryption combined with data exfiltration, with stolen-data samples posted to the leak site
  • High-volume leak-site posting, listing multiple new victims in single batches
  • Targeting of exposed network edge infrastructure at critical-infrastructure and manufacturing organizations (vendor research, 2025)
  • Reported Linux/ESXi encryptor variant expanding beyond Windows (vendor research, 2025)
  • Global targeting across Latin America, Europe, and Asia per leak-site listings
Targeted sectors
manufacturingcritical infrastructurelegal/professional servicesinsurancelogisticsfinancial services/fintechIT serviceshospitality
Notable public victims

Piramide Seguros, on-us, PT All Cosmos Biotek, Siam Stabilizers and Chemicals Co., Ltd. (SSC), MHE9 Logistica Ltda, Dissinger and Dissinger Law Firm, New Tiles S.L.

CVEs linked to their intrusions
Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
Varela Hermanos · Apr 23, 2025Industry: Beverage Manufacturing Location: Panama Publish Date: Expired URL: varelahermanos.com
Dar Al Teb · Apr 23, 2025Industry: Hospital & Healthcare Location: Egypt Publish Date: Expired URL: daralteb.com
Shinko Shoji · Apr 23, 2025Industry: Real Estate Location: Japan Publish Date: Expired URL: www.shinkocorp.co.jp

In the newsAll →

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .