National Office of Investigation Probing Attacks Related to GUNRA Ransomware

South Korean and U.S. investigative authorities have identified the latest tactics used by ransomware groups targeting corporations and have issued a security advisory to help prevent damage.


The National Office of Investigation at the National Police Agency announced on August 11 that, together with the U.S. Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), Department of Defense Cyber Crime Center (DC3), and U.S. Secret Service (USSS), it has issued a joint cyber security advisory concerning the "GUNRA" ransomware. The National Office of Investigation is currently investigating attacks related to the GUNRA ransomware and plans to rapidly share additional threat information with relevant agencies and companies.

"Pay or Corporate Data Will Be Exposed": National Police Agency and FBI Issue Ransomware Warning View original image

GUNRA is an international ransomware group whose activities have been confirmed since last year. Recently, it has also begun operating as "Ransomware-as-a-Service (RaaS)," a crime model in which ransomware developers provide attack tools to other criminals and share ransom proceeds following a successful breach. In particular, the group has been expanding its attacks across various sectors domestically and internationally—including critical infrastructure, finance, healthcare, and manufacturing—requiring heightened vigilance.


According to analysis by the National Police Agency and FBI, GUNRA ransomware attackers exploit vulnerabilities in systems such as security equipment to gain access to target networks, thereby infiltrating organizations and companies. They do not simply encrypt files; instead, they employ a "double extortion" tactic, stealing internal data before demanding payment. To further these attacks, they operate dark web sites, publicly posting lists and samples of exfiltrated data from victim companies, and threatening to sell or release these materials unless ransom demands are met.



The South Korean and U.S. authorities emphasized that blocking the initial intrusion is the most effective defense. They stressed that it is crucial for companies to adhere to basic security practices, such as controlling external access through virtual private networks (VPNs) and secure remote access, applying the latest security updates (patches), implementing strong account management via multi-factor authentication, and establishing robust backup systems.


This content was produced with the assistance of AI translation services.

© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.

Today’s Briefing