US Bank investigates LockBit's claims as ransomware crims set pay-or-leak deadline
Follow the money
Gunra is a ransomware-as-a-service operation leveraging a double-extortion model to target government, critical infrastructure, and other organizations across multiple sectors worldwide, with initial access primarily achieved through exploitation of known vulnerabilities in VPN gateways and firewall appliances. The threat actors employ sophisticated lateral movement techniques, credential theft, and data exfiltration before deploying ChaCha20 + RSA-4096 encryption, while using tools like Impacket and secretsdump.py to move laterally and extract credentials from domain controllers. Organizations should prioritize patching exploited vulnerabilities, implementing offline immutable backups, enforcing multi-factor authentication, and segmenting networks to contain potential lateral movement.
Read full article at CISA Advisories ↗Follow the money
Because apparently even ransomware gangs can't trust the people they do business with
These companies often have the hardest time balancing their roles as suppliers and customers, according to the risk management firm Black Kite.
The FBI warned that the RaaS operation has significantly enhanced its tactics, techniques and procedures, making it harder for defenders to counter