Ransomware
Verified open source
Threat actor: Gunra
Intelligence with traceable provenance. EudorIA retains technical indicators acquired from supported feeds, with source, date and context. Shareable IOCs are available in the STIX feeds; detection and blocking actions require an assessment of validity, confidence and applicability to the customer's environment. Browse STIX feeds
EudorIA operational summary
Priority 90/100
What it means
Una fonte OSINT pubblica associa Threat actor: Gunra al gruppo Gunra. La notizia non e stata verificata in modo indipendente da EudorIA.
Why it matters
Il segnale puo aiutare il monitoraggio del rischio di filiera, ma non deve essere trattato come conferma di compromissione.
Recommended actions
- Correlare il segnale con fonti indipendenti e telemetria autorizzata.
- Evitare comunicazioni esterne finche l'attribuzione non e confermata.
Potential operational benefits
- Security Assessment
- Managed WAF
- XDR per utente/mese
- Managed Next-Generation Firewall
- SOC as a Service
- Backup e continuita operativa
Relevant controlsInitial AccessLateral MovementImpact
AudienceSOCCISOManagement
Text acquired from the source
Gunra Ransomware, un RaaS derivato da Conti1, è attivo con picco operativo tra l'agosto 2026. Colpisce multi-settorialmente aree come Sanità e Servizi Finanziari in tutto il mondo, utilizzando tecniche di initial access (T1190) e doppia estorsione.
- Source
- EudorIA CTI Research
- Publishing entity
- EudorIA CTI Research
- Entity type
- ransomware operation
- Publication
- 11/08/2026 02:00
- Sharing
- TLP:clear
- MITRE ATT&CK
- T1190 - Exploit Public-Facing Application, T1614 - Data Encrypted for Impact, T1020 - Automated Exfiltration, T1567 - Exfiltration Over Web Service, TA0008 - Lateral Movement, T1190, T1021, T1486, T1659
- Classification
- Informational
- Group attributed by the source
- Gunra
- Stated country
- Stati Uniti