← Back to feed
Breaches & RansomwareEmerging1 sourceAug 13, 2026 · 06:31via CyberPress

Gunra Targets Primary and Disaster-Recovery Backups Before File Encryption

Brief

Gunra ransomware operators are taking a destructive approach designed to remove every easy recovery path before locking victim files.

In a documented incident, the group deleted backup and archived data stored at both the primary data center and the disaster-recovery site before and after deploying ransomware.

The tactic greatly increases pressure on victims because even organizations with standard backup plans may find their recovery infrastructure unavailable.

Gunra emerged in April 2025 as a ransomware family linked to the leaked Conti source code .

It later expanded into a ransomware-as-a-service operation, allowing affiliates to use a management panel, configurable ransomware builder, cross-platform payloads, and operational documentation.

U. S. and South Korean agencies have also observed the group using the Golden Community name.

The threat uses a double-extortion model.

Read more on CyberPress