EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Ransomware

Threat actor: Gunra

Verified open source
Intelligence with traceable provenance. EudorIA retains technical indicators acquired from supported feeds, with source, date and context. Shareable IOCs are available in the STIX feeds; detection and blocking actions require an assessment of validity, confidence and applicability to the customer's environment. Browse STIX feeds
EudorIA operational summary

What it means

Priority 90/100

Una fonte OSINT pubblica associa Threat actor: Gunra al gruppo Gunra. La notizia non e stata verificata in modo indipendente da EudorIA.

Why it matters

Il segnale puo aiutare il monitoraggio del rischio di filiera, ma non deve essere trattato come conferma di compromissione.

Potential operational benefits

  • Security Assessment
  • Managed WAF
  • XDR per utente/mese
  • Managed Next-Generation Firewall
  • SOC as a Service
  • Backup e continuita operativa
Indications to confirm against the customer's technical and organisational perimeter.
Relevant controlsInitial AccessLateral MovementImpact
AudienceSOCCISOManagement

Text acquired from the source

Gunra Ransomware, un RaaS derivato da Conti1, è attivo con picco operativo tra l'agosto 2026. Colpisce multi-settorialmente aree come Sanità e Servizi Finanziari in tutto il mondo, utilizzando tecniche di initial access (T1190) e doppia estorsione.

Source
EudorIA CTI Research
Publishing entity
EudorIA CTI Research
Entity type
ransomware operation
Publication
11/08/2026 02:00
Sharing
TLP:clear
MITRE ATT&CK
T1190 - Exploit Public-Facing Application, T1614 - Data Encrypted for Impact, T1020 - Automated Exfiltration, T1567 - Exfiltration Over Web Service, TA0008 - Lateral Movement, T1190, T1021, T1486, T1659
Classification
Informational
Group attributed by the source
Gunra
Stated country
Stati Uniti
Open the original source