news.mlab.sh
Back to the feed
ransomware

#StopRansomware: Gunra Ransomware

Critical
Summary

The FBI, CISA, and other agencies have issued a joint advisory regarding the Gunra ransomware threat, a sophisticated double-extortion variant derived from the Conti ransomware. Gunra has rapidly expanded through a RaaS affiliate program, operating on the dark web and utilizing a custom Tor-based negotiation portal. The group employs a double-extortion model, exfiltrating data before encryption and leveraging various techniques to evade detection, including log deletion and filtering of system files. Initial access is frequently gained through exploiting vulnerabilities in internet-facing devices, particularly VPN appliances, and leveraging credential-dumping techniques. The group is actively recruiting penetration testers to assist with initial access, and has demonstrated a capacity to exfiltrate large volumes of data via services like Mega.

Read the full article at CISA Advisories

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.