"Pay or Corporate Data Will Be Exposed": National Police Agency and FBI Issue Ransomware Warning
National Office of Investigation Probing Attacks Related to GUNRA Ransomware
South Korean and U.S. investigative authorities have identified the latest tactics used by ransomware groups targeting corporations and have issued a security advisory to help prevent damage.
The National Office of Investigation at the National Police Agency announced on August 11 that, together with the U.S. Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), Department of Defense Cyber Crime Center (DC3), and U.S. Secret Service (USSS), it has issued a joint cyber security advisory concerning the "GUNRA" ransomware. The National Office of Investigation is currently investigating attacks related to the GUNRA ransomware and plans to rapidly share additional threat information with relevant agencies and companies.
GUNRA is an international ransomware group whose activities have been confirmed since last year. Recently, it has also begun operating as "Ransomware-as-a-Service (RaaS)," a crime model in which ransomware developers provide attack tools to other criminals and share ransom proceeds following a successful breach. In particular, the group has been expanding its attacks across various sectors domestically and internationally—including critical infrastructure, finance, healthcare, and manufacturing—requiring heightened vigilance.
According to analysis by the National Police Agency and FBI, GUNRA ransomware attackers exploit vulnerabilities in systems such as security equipment to gain access to target networks, thereby infiltrating organizations and companies. They do not simply encrypt files; instead, they employ a "double extortion" tactic, stealing internal data before demanding payment. To further these attacks, they operate dark web sites, publicly posting lists and samples of exfiltrated data from victim companies, and threatening to sell or release these materials unless ransom demands are met.
Hot Picks Today
"Not Even Daiso, but Prices from 1,000 to 7,000 Won" Crowds Flock... This Place Becomes Millennial & Gen Z Shopping Hotspot
- "Is It Really This Big?" World Number One in Sight... K-Beauty’s Surge Captivates Foreign Consumers with Trusted Korean Products
- A Real-Life Fairytale: 26-Year-Old Car Salesman Revealed to Be a Prince
- "I'm Not Selling, I'm Still Waiting"... Why Jeon Wonju Holds Firm Despite a 9,000% Return on SK hynix
- "Does This Really Work?" Just Add Cold Water... Cup Noodles Sell Out in 68 Years' First Craze
The South Korean and U.S. authorities emphasized that blocking the initial intrusion is the most effective defense. They stressed that it is crucial for companies to adhere to basic security practices, such as controlling external access through virtual private networks (VPNs) and secure remote access, applying the latest security updates (patches), implementing strong account management via multi-factor authentication, and establishing robust backup systems.
© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.