The Korean National Police Agency, together with U.S. law enforcement, disclosed the latest attack techniques of the international ransomware group "GUNRA" and urged domestic and overseas institutions and corporations to strengthen security.
The National Office of Investigation (NOI) of the Korean National Police Agency said on the 11th that, together with the Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), the Ministry of National Defense Defense Cyber Crime Center (DC3), and the United States Secret Service (USSS), it distributed a South Korea-U.S. joint cyber security advisory on GUNRA ransomware.
GUNRA is an international ransomware group whose activity has been confirmed since last year. Recently, it was found to be operating in a "ransomware-as-a-service (RaaS)" model, providing attack tools to other criminals and sharing criminal revenue.
According to an analysis by the police and the FBI, GUNRA attackers exploited system vulnerabilities, including in security appliances, to obtain access privileges to target networks, then infiltrated inside corporations and institutions to distribute ransomware. Their targets are expanding to include critical infrastructure as well as finance, healthcare, and manufacturing.
They not only encrypted files but also used a "double extortion" tactic, exfiltrating internal data in advance and then demanding money.
In particular, they operated a site on the Dark Web (a secret internet space accessible only with dedicated software), posted lists of victim corporations and portions of stolen data, and in some cases threatened to sell or disclose the stolen data unless the ransom was paid.
To prevent ransomware attacks, the police recommended inspecting external access paths such as virtual private networks (VPNs) and remote access and applying the latest security patches, while strengthening account security through multi-factor authentication.
They also said it is necessary to establish a system to securely back up important data and to closely inspect system logs and anomalous behavior using the indicators of compromise included in this advisory.
The police emphasized that if ransomware infection or signs of intrusion are suspected, victims should not contact or negotiate directly with the attackers, but report promptly to the police.
The National Office of Investigation (NOI) of the Korean National Police Agency is currently investigating attacks related to GUNRA ransomware and plans to share any additional threat intelligence obtained with relevant agencies and corporations. In addition, it will continue to enhance response capabilities by cooperating with the international community and strengthening public-private cooperation systems to prepare for similar ransomware attacks.