#StopRansomware: Gunra Ransomware

    Date: 08/11/2026

    Severity: Critical

    Summary

    Gunra is a ransomware-as-a-service (RaaS) operation used by affiliates to target government, critical infrastructure, and other organizations through data encryption, data exfiltration, and double-extortion tactics. CVE-2024-55591 and CVE-2025-24472 allow threat actors to exploit scheduled tasks on vulnerable FortiOS firewall devices. Gunra victims have been observed across the Americas, Europe, Middle East, Africa, and Asia-Pacific, affecting sectors including healthcare and public health, financial services and insurance, critical manufacturing and construction, transportation and logistics, government services and facilities, utilities, academia, media and communications, retail, and professional/nonprofit services. 

    Indicators of Compromise (IOC) List

    Domain/URLs

    Datapub.news

    gunrabxbig445sjqa535uaymzerj6fp4nwc6ngc2xughf2pedjdhk4ad.onion

    lgiil72vkmdtbc3qv4tyq6wedyjxqr2qd4ze7xl2cxgerdnymxj7soqd.onion

    nsnhzysbntsqdwpys6mhml33muccsvterxewh5rkbmcab7bg2ttevjqd.onion

    IP Address

    23.239.119.2

    23.239.119.3

    23.239.119.4 

    23.239.119.5

    23.239.119.6

    86.54.28.216

    103.125.234.14

    70.36.99.82

    211.21.210.181

    123.184.143.105

    182.204.21.240

    182.204.16.112

    123.244.187.144

    182.204.39.118

    67.43.53.10

    123.246.37.108

    91.201.66.146

    Hashes

    2dc70a12d158d437e45a55b1d52f3d61c6082a1e1667573302ba3b62813e2751

    834efe9b392c6c000877ea5613a079445affc16fe8af5997d68c55cafc95e5d1

    91f8fc7a3290611e28a35a403fd815554d9d856006cc2ee91ccdb64057ae53b0

    a82e496b7b5279cb6b93393ec167dd3f50aff1557366784b25f9e51cb23689d9

    Email

    a00f105546345756@proton.me

    4569f6322bc3b22e9@proton.me

    ilovemycubscout@gmail.com

    6449a3c1e612168526@proton.me

    Tox ID

    2507312EC10BB44ED9DAA04E3C5C27E8C13154649B1A02E73ACFAE1681EE0208D05133A8FB22

    0FE87CED0C611AE97E049C64288557F49E8271E91399E849328B078DA789A573031783235BEF

    47829AF1C943D4C296C910706923AS199BDA4995B076ED9A9016F7DEF161D445DF00F13E6900

    9500B1A73716BCF40745086F7184A33EA0141B7D3F852431C8FDD2E1E8FAF9277E9FDC117B47

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    domainname like "Datapub.news" or url like "Datapub.news" or siteurl like "Datapub.news" or domainname like "nsnhzysbntsqdwpys6mhml33muccsvterxewh5rkbmcab7bg2ttevjqd.onion" or url like "nsnhzysbntsqdwpys6mhml33muccsvterxewh5rkbmcab7bg2ttevjqd.onion" or siteurl like "nsnhzysbntsqdwpys6mhml33muccsvterxewh5rkbmcab7bg2ttevjqd.onion" or domainname like "gunrabxbig445sjqa535uaymzerj6fp4nwc6ngc2xughf2pedjdhk4ad.onion" or url like "gunrabxbig445sjqa535uaymzerj6fp4nwc6ngc2xughf2pedjdhk4ad.onion" or siteurl like "gunrabxbig445sjqa535uaymzerj6fp4nwc6ngc2xughf2pedjdhk4ad.onion" or domainname like "lgiil72vkmdtbc3qv4tyq6wedyjxqr2qd4ze7xl2cxgerdnymxj7soqd.onion" or url like "lgiil72vkmdtbc3qv4tyq6wedyjxqr2qd4ze7xl2cxgerdnymxj7soqd.onion" or siteurl like "lgiil72vkmdtbc3qv4tyq6wedyjxqr2qd4ze7xl2cxgerdnymxj7soqd.onion"

    Detection Query 2 :

    dstipaddress IN ("182.204.21.240","91.201.66.146","103.125.234.14","23.239.119.2","23.239.119.3","23.239.119.6","86.54.28.216","70.36.99.82","211.21.210.181","123.246.37.108","123.184.143.105","67.43.53.10","23.239.119.4","182.204.16.112","23.239.119.5","182.204.39.118","123.244.187.144") or srcipaddress IN ("182.204.21.240","91.201.66.146","103.125.234.14","23.239.119.2","23.239.119.3","23.239.119.6","86.54.28.216","70.36.99.82","211.21.210.181","123.246.37.108","123.184.143.105","67.43.53.10","23.239.119.4","182.204.16.112","23.239.119.5","182.204.39.118","123.244.187.144")

    Detection Query 3 :

    sha256hash IN ("91f8fc7a3290611e28a35a403fd815554d9d856006cc2ee91ccdb64057ae53b0","834efe9b392c6c000877ea5613a079445affc16fe8af5997d68c55cafc95e5d1","a82e496b7b5279cb6b93393ec167dd3f50aff1557366784b25f9e51cb23689d9","2dc70a12d158d437e45a55b1d52f3d61c6082a1e1667573302ba3b62813e2751")

    Detection Query 4 :

    from IN ("a00f105546345756@proton.me","4569f6322bc3b22e9@proton.me","ilovemycubscout@gmail.com","6449a3c1e612168526@proton.me") or to IN ("a00f105546345756@proton.me","4569f6322bc3b22e9@proton.me","ilovemycubscout@gmail.com","6449a3c1e612168526@proton.me") or reception IN ("a00f105546345756@proton.me","4569f6322bc3b22e9@proton.me","ilovemycubscout@gmail.com","6449a3c1e612168526@proton.me")

    Reference: 

    https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-222a        


    Tags

    MalwareThreat ActorVulnerabilityExploitCISARansomwareGunraExtortionExfiltrationRaaSCritical InfrastructureGovernment Services and FacilitiesCVE-2024CVE-2025AmericaEuropeThe Middle EastAfricaAsiaHealthcare and Public HealthFinancial ServicesTransportation SystemsCommunicationsEducationRetail

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags