HomeSecurityGunra ransomware attacks Windows and Linux

Gunra ransomware attacks Windows and Linux

The cyberthreat landscape continues to evolve, with Gunra ransomware appearing in April 2025 and already establishing itself as a significant threat to organizations worldwide.

Gunra ransomware

The team has demonstrated a systematic approach to compromising both Windows and Linux environments. Organizations from many industries have reported successful infection attempts.

Gunra operates on a familiar but effective ransomware model: it encrypts critical files on infected systems, extracts sensitive data from compromised organizations , and demands ransom payments, threatening public disclosure if the demands are not met.

See also: GhostGrab: New Android malware steals banking credentials

What sets Gunra apart from other ransomware operators is the deliberate development of platform-specific variants. The group distributes their malware in two different formats: executable files for Windows environments and ELF binaries for Linux systems.

This strategic approach allows them to maximize the attack surface and penetrate diverse infrastructure environments maintained by many organizations. ASEC identified that Gunra ransomware operates through a command-line interface that requires multiple parameters to execute its encryption routines.

Gunra ransomware attacks Windows and Linux

The malware performs validity checks on the provided arguments before starting the main execution routine, ensuring that all necessary parameters are present and valid.

Gunra ransomware: Cryptographic weakness and decryption vulnerability

Technical analysis reveals a critical vulnerability in the ELF version of the Gunra ransomware, which fundamentally weakens the encryption scheme. ASEC researchers discovered that the malware uses the ChaCha20 encryption algorithm, with a cryptographically insecure random number generation function.

See also: Beast Ransomware: Learn everything about the new threat

The vulnerability arises from the seed generation process, which relies on the time() function to generate predictable values ​​for the rand() function. The flaw becomes apparent when examining how the 32-byte encryption key and 12-byte nonce values. When multiple encryption iterations are performed in extremely short time intervals, the seed value remains the same across different execution threads. This causes the rand() function to produce identical byte sequences, resulting in the encryption keys and nonce arrays containing repeating byte patterns. As a result, ChaCha20 keys become cryptographically weak and vulnerable to brute-force attacks on 256 possible byte values.

This cryptographic bypass allows decryption of files with brute-force techniques based on byte values ​​ranging from 0x00 to 0xFF.

See also: Atroposia malware kit increases cybercrime

Gunra ransomware attacks Windows and Linux

On the other hand, the Windows EXE implements ChaCha8 encryption with key generation via the CryptGenRandom() API, using cryptographically secure random number generation that makes decryption practically impossible. This difference between the implementations highlights the different security stances on different platforms.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS