Korea, U.S. Team Up Against GUNRA Ransomware Gang Targeting Firms | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


Police file photo

Attacks by international ransomware gangs are spreading, in which the groups breach security vulnerabilities at companies and institutions, extract internal data, encrypt files and then threaten to publish the stolen material on the dark web if a ransom is not paid. South Korean police, the U.S. Federal Bureau of Investigation (FBI) and other government agencies from both countries have released the latest attack methods and indicators of compromise identified through a joint investigation, launching a coordinated response.

The National Office of Investigation under the Korean National Police Agency said on the 11th that it had distributed a joint Korea-U.S. cybersecurity advisory on the international ransomware group “GUNRA,” together with the FBI, the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), the Department of Defense Cyber Crime Center (DC3) and the U.S. Secret Service (USSS).

GUNRA is an international ransomware group confirmed to have been active since last year. More recently, it has also operated as a “ransomware-as-a-service” (RaaS) scheme, in which ransomware developers provide attack tools to other criminals and split the ransom when an attack succeeds. Its targets have also widened to various sectors at home and abroad, including critical infrastructure, finance, healthcare and manufacturing.

An analysis by the police and the FBI found that GUNRA attackers exploit vulnerabilities in systems such as security equipment to gain network access before penetrating the internal networks of companies or institutions.

Notably, the group does not stop at simply encrypting files and demanding money. It uses a so-called “double extortion” method, first extracting internal data and then encrypting the files. Investigators also confirmed that the group posts lists of victim companies and portions of stolen material on its own dark web site, threatening to sell or release the data if the ransom is not paid.

The advisory contains GUNRA’s latest attack techniques and indicators of compromise that Korean and U.S. investigators obtained during the joint investigation. The two countries plan to share this with institutions and companies at home and abroad to help detect similar attacks early and prevent damage.

The Korean and U.S. authorities recommended controlling external access such as VPNs and remote connections and applying the latest security patches to prevent ransomware attacks. They also called for stronger account management through multi-factor authentication and the establishment of secure backup systems. If signs of infection or a breach are found, they advised, victims should not contact the attackers directly but report the case to police.

The National Office of Investigation is currently investigating attacks linked to the GUNRA ransomware. It plans to share any additional threat intelligence it obtains with related agencies and companies, while strengthening cooperation with the international community and the private sector.

——————————————————–


Click Here For The Original Source.

.........................