South Korea's Korean National Police Agency has joined forces with the US Federal Bureau of Investigation, the Cybersecurity and Infrastructure Security Agency, the National Security Agency, the Defense Department's Cyber Crime Center and the US Secret Service to issue a joint cybersecurity advisory on the international ransomware group GUNRA.
The Korean National Police Agency said Tuesday that government agencies from both countries published the joint advisory to raise awareness of GUNRA's hacking methods and urge organizations to strengthen their cybersecurity measures.
The advisory incorporates the latest attack techniques and indicators of compromise gathered during joint investigations by law enforcement agencies from both countries, and is intended to help domestic and international organizations and businesses prevent further damage.
According to analysis by the Korean National Police Agency and the FBI, GUNRA operators infiltrate companies and institutions by gaining unauthorized network access before deploying ransomware. The group also runs dark web sites where it posts samples of stolen internal data and demands payment from victims.
Investigators have also confirmed that the group has recently been operating as a ransomware-as-a-service model, providing attack tools to other criminals and splitting the proceeds when attacks succeed.
A Korean National Police Agency official said the agency is currently investigating attacks linked to GUNRA and plans to quickly share additional threat intelligence with relevant agencies and businesses. "The group is expanding its attacks across a wide range of sectors at home and abroad, including finance, healthcare and manufacturing, and extra vigilance is required," the official said.
The official added that the agency intends to strengthen public-private cooperation and international partnerships to prepare for similar ransomware attacks in the future, and will continue to build its response capabilities.
arin@heraldcorp.com
