DistantNews
Support us
New 'Ransomware-as-a-Service' Targets Hundreds Globally
๐Ÿ‡ฐ๐Ÿ‡ท South Korea /Crime & Justice

New 'Ransomware-as-a-Service' Targets Hundreds Globally

From Dong-A Ilbo · () Korean

Translated from Korean, summarized and contextualized by DistantNews.

At a glance

News Official statement Under investigation
  • A new type of ransomware, dubbed 'GUNRA,' has been identified, targeting hundreds of companies and institutions globally, including in South Korea.
  • This ransomware employs a 'double extortion' tactic, stealing data before encrypting it and threatening to sell or leak the stolen information.
  • Authorities warn that GUNRA is also operating as 'ransomware-as-a-service,' allowing less technically skilled criminals to participate by renting the hacking tools and sharing profits.

South Korean and U.S. cybersecurity authorities have issued a joint warning about a sophisticated new ransomware variant, identified as 'GUNRA,' which has targeted hundreds of businesses and organizations worldwide. The ransomware group has been active since last year, exploiting system vulnerabilities to infiltrate various sectors, including critical infrastructure, finance, healthcare, and manufacturing.

Unlike traditional ransomware that solely encrypts files, GUNRA employs a more aggressive 'double extortion' strategy. Before encrypting data, the attackers first exfiltrate sensitive information. They then use dark web sites to publish lists of victim companies and samples of the stolen data, threatening to sell or release the full dataset if a ransom is not paid.

Adding to the concern, GUNRA is reportedly operating under a 'ransomware-as-a-service' model. This means the developers of the ransomware tools lease their hacking kits to other criminals. Those who successfully carry out attacks share the profits with the developers, lowering the barrier to entry for cybercrime and potentially increasing the frequency and scale of attacks.

In response, the National Investigation Headquarters of the Korean National Police Agency, in collaboration with the FBI, CISA, and NSA in the U.S., has released a joint cybersecurity advisory. The advisory urges organizations to implement robust security measures, including controlling external access via VPNs and remote connections, applying the latest security patches, strengthening account management with multi-factor authentication, and maintaining secure backup systems.

DistantNews Editorial

Originally published by Dong-A Ilbo in Korean. Translated, summarized, and contextualized by our editorial team with added local perspective. Read our editorial standards.