news.mlab.sh
Back to the feed
ransomware

Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks

High
Image: The Hacker News
Summary

The Gunra ransomware group, linked to state-sponsored actors, is aggressively targeting critical infrastructure and organizations globally, leveraging vulnerabilities in Fortinet and Schneider Electric appliances to gain initial access and deploy ransomware. The group employs a double extortion model, combining data exfiltration and encryption, and has been observed using sophisticated techniques like session hijacking, credential dumping, and exploiting MFA bypasses. South Korean and U.S. agencies have issued warnings about the group's activities, which are linked to a broader campaign involving state-sponsored actors and the use of tools like Struggle and Brandoor. Organizations are urged to prioritize patching, segmentation, and robust backups to mitigate the risk.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.