#StopRansomware: Gunra Ransomware
The FBI, CISA, and other agencies have issued a joint advisory regarding the Gunra ransomware threat, a sophisticated double-extortion variant derived from the Conti ransomware. Gunra has rapidly expanded through a RaaS affiliate program, operating on the dark web and utilizing a custom Tor-based negotiation portal. The group employs a double-extortion model, exfiltrating data before encryption and leveraging various techniques to evade detection, including log deletion and filtering of system files. Initial access is frequently gained through exploiting vulnerabilities in internet-facing devices, particularly VPN appliances, and leveraging credential-dumping techniques. The group is actively recruiting penetration testers to assist with initial access, and has demonstrated a capacity to exfiltrate large volumes of data via services like Mega.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data