Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Gunra Ransomware Group Hitting Multiple Sectors

Дата публикации: 01-01-1970 00:00:00

An advisory issued jointly this week by the Federal Bureau of Investigation, Cybersecurity and Infrastructure Security Agency, Department of Defense Cyber Crime Center, National Security Agency, U.S. Secret Service, and the Republic of Korea’s National Police Agency alerted organizations about an emerging threat from the Gunra ransomware group and provided guidance on detection and mitigation.
Gunra emerged in April 2025 as a sophisticated double-extortion ransomware variant derived from the leaked Conti ransomware source code. It expanded in 2026 as a structured ransomware-as-a-service (RaaS) affiliate program advertised on dark web forums for cybercriminals. Gunra actors demand ransom through a customized Tor-based negotiation portal and threaten to publish exfiltrated data on a leak site if victims do not comply. According to the alert, Gunra is actively recruiting penetration testers and ethical hackers as initial access brokers, offering a share of the ransom profits in exchange for enterprise network access. I’m hoping ethical hackers will remain “ethical.”
Organizations listed on the actors’ leak site have included multiple business sectors across the Americas, Europe, the Middle East, Africa, and the Asia-Pacific region including:
• Healthcare and public health;
• Financial services and insurance;
• Critical manufacturing and construction;
• Transportation systems and logistics;
• Government services and facilities;
• Utilities;
• Academia;
• Media and communications;
• Retail; and
• Professional and nonprofit services.
Organizations in these sectors are urged to implement the recommendations for mitigation including:
• Prioritizing the patching of known exploited vulnerabilities in internet-facing systems, including virtual private network (VPN) gateways and remote desktop protocol (RDP)-exposed infrastructure;
• Implementing and regularly testing offline, immutable backups stored in a physically separate, segmented location to ensure recovery without paying a ransom; and
• Segmenting networks to restrict lateral movement from an initially compromised device to other systems within the organization.
The advisory provides technical details that should be reviewed and implemented by IT professionals, including pinpointing the legitimate tools that are being used by Gunra that can evade existing monitoring tools.


Основное содержимое страницы с новостью.

Gunra Ransomware Group Hitting Multiple Sectors

Thursday, August 13, 2026

An advisory issued jointly this week by the Federal Bureau of Investigation, Cybersecurity and Infrastructure Security Agency, Department of Defense Cyber Crime Center, National Security Agency, U.S. Secret Service, and the Republic of Korea’s National Police Agency alerted organizations about an emerging threat from the Gunra ransomware group and provided guidance on detection and mitigation.

Gunra emerged in April 2025 as a sophisticated double-extortion ransomware variant derived from the leaked Conti ransomware source code. It expanded in 2026 as a structured ransomware-as-a-service (RaaS) affiliate program advertised on dark web forums for cybercriminals. Gunra actors demand ransom through a customized Tor-based negotiation portal and threaten to publish exfiltrated data on a leak site if victims do not comply. According to the alert, Gunra is actively recruiting penetration testers and ethical hackers as initial access brokers, offering a share of the ransom profits in exchange for enterprise network access. I’m hoping ethical hackers will remain “ethical.”

Organizations listed on the actors’ leak site have included multiple business sectors across the Americas, Europe, the Middle East, Africa, and the Asia-Pacific region including:

• Healthcare and public health;

• Financial services and insurance;

• Critical manufacturing and construction;

• Transportation systems and logistics;

• Government services and facilities;

• Utilities;

• Academia;

• Media and communications;

• Retail; and

• Professional and nonprofit services.

Organizations in these sectors are urged to implement the recommendations for mitigation including:

• Prioritizing the patching of known exploited vulnerabilities in internet-facing systems, including virtual private network (VPN) gateways and remote desktop protocol (RDP)-exposed infrastructure;

• Implementing and regularly testing offline, immutable backups stored in a physically separate, segmented location to ensure recovery without paying a ransom; and

• Segmenting networks to restrict lateral movement from an initially compromised device to other systems within the organization.

The advisory provides technical details that should be reviewed and implemented by IT professionals, including pinpointing the legitimate tools that are being used by Gunra that can evade existing monitoring tools.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1The ‘year of AI’: 2026 sees influx of ransomware attacks-2626-06-2026
2Ransomware in 2026: More groups, more victims, no slowdown012.1424-07-2026
3DragonForce Ransomware Is Hiding in Microsoft Teams Traffic0717-06-2026
4Researchers Uncover First Fully Agentic AI Ransomware Attack0806-07-2026
5NCC Group Warns Ransomware, State Hackers, and AI Fraud Tools Are Colliding0724-06-2026
6Crypto Exploits Siphon Record $1,100,000,000 From Digital Asset Protocols in Six Months: Report033.7303-08-2026
7CISA gives US federal agencies three days to fix a VPN bug under attack by a ransomware gang0809-06-2026
8How ransomware syndicates weaponize corporate-style organization0730-06-2026
9AI Agent Carries Out Ransomware Attack in Possible Cybercrime First0807-07-2026

Классификация: Пресс-релизы. Схожих патентов: 0. Схожих новостей: 9. Тональность: 0. Информативность: 9.58. Источник: www.natlawreview.com.