← Back
RansomwareCISA Advisories·1 week ago

#StopRansomware: Gunra Ransomware

Gunra is a ransomware-as-a-service operation leveraging a double-extortion model to target government, critical infrastructure, and other organizations across multiple sectors worldwide, with initial access primarily achieved through exploitation of known vulnerabilities in VPN gateways and firewall appliances. The threat actors employ sophisticated lateral movement techniques, credential theft, and data exfiltration before deploying ChaCha20 + RSA-4096 encryption, while using tools like Impacket and secretsdump.py to move laterally and extract credentials from domain controllers. Organizations should prioritize patching exploited vulnerabilities, implementing offline immutable backups, enforcing multi-factor authentication, and segmenting networks to contain potential lateral movement.

Read full article at CISA Advisories

Related Articles