[Photo: Shutterstock]

The National Police Agency's National Investigation Headquarters said on Monday it distributed a joint South Korea-U.S. cybersecurity advisory on the 'Gunra (GUNRA)' ransomware with the U.S. Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), the Department of Defense Cyber Crime Center (DC3) and the U.S. Secret Service (USSS).

The advisory was distributed as part of efforts to help organisations and companies in South Korea and abroad prevent damage by reflecting the latest attack techniques and indicators of compromise secured during a joint investigation by investigative agencies in the two countries.

Gunra is an international ransomware group whose activity has been confirmed since 2025. Recently it has also been operated in the form of Ransomware as a Service (RaaS), and it is expanding attacks across various sectors in South Korea and abroad, including major infrastructure, finance, healthcare and manufacturing.

According to analyses by the National Police Agency and the FBI, Gunra ransomware attackers exploit system vulnerabilities, including in security equipment, to obtain network access to targets. They infiltrate organisations and spread ransomware. They do not stop at encrypting files. They use "double-extortion" attacks that first steal internal data and then demand money. To do so, they operate dark web sites, post lists of victim companies and some of the stolen materials, and also threaten to sell or disclose the stolen data if the ransom is not paid.

The National Police Agency stressed that blocking initial infiltration is the most effective response to ransomware. It said it is essential to follow basic security rules, including controlling external access such as virtual private networks (VPNs) and remote access, applying the latest security updates (security patches), strengthening account management by applying multi-factor authentication, and activating secure backup systems.

It also urged organisations to closely check system log information and anomalous behaviour based on the indicators of compromise included in the advisory, and to refrain from directly contacting attackers. It asked that suspected ransomware infections or signs of compromise be promptly reported to the police.

The National Police Agency's National Investigation Headquarters is investigating attacks related to the Gunra ransomware. It plans to quickly share additional threat information with relevant agencies and companies.

Keyword

#National Police Agency #FBI #CISA #NSA #Gunra
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.