Gunra Attackers Hijack RDP Sessions to Compromise Active Directory
Key Takeaways The Gunra ransomware group has rapidly escalated into a significant threat, targeting critical sectors globally. Attackers exploit authentication bypass vulnerabilities in FortiOS and...
Key Takeaways
- The Gunra ransomware group has rapidly escalated into a significant threat, targeting critical sectors globally.
- Attackers exploit authentication bypass vulnerabilities in FortiOS and FortiProxy (CVE-2024-55591, CVE-2025-24472) to gain initial access.
- The group leverages stolen RDP sessions and legitimate remote management tools to compromise Active Directory and IT workstations, facilitating widespread network encryption.
- Gunra employs a double extortion model, exfiltrating terabytes of sensitive data before encrypting systems on both Windows and Linux networks.
- Effective mitigation requires urgent patching, robust identity security, vigilant monitoring of remote access, and comprehensive backup strategies.
The Gunra ransomware operation has quickly evolved from a nascent threat to a formidable force targeting enterprises worldwide, according to recent analysis. This sophisticated group not only encrypts systems across Windows and Linux environments but also engages in extensive data exfiltration, posing a severe double extortion risk to its victims.
Table Of Content
Initially identified in Windows systems in April 2025, Gunra expanded its capabilities with a Linux variant and launched a ransomware-as-a-service (RaaS) program by January 2026. The group’s tactics bear a resemblance to the leaked Conti source code, employing a dual approach of locking down victim files and threatening to publish or sell stolen data.
Analysts at Picus Security have detailed how Gunra affiliates exploit critical authentication bypass vulnerabilities in FortiOS and FortiProxy, specifically CVE-2024-55591 and CVE-2025-24472, to achieve elevated administrative access. In a report shared with Cyber Security News (CSN), Picus Security highlighted that the campaign has indiscriminately targeted government entities, critical infrastructure, healthcare providers, financial institutions, and nonprofit organizations across the globe.
Before deploying their ransomware, attackers systematically collect vast quantities of sensitive information, including documents, databases, personal records, and internal emails. Reported data theft volumes have reached tens of terabytes, underscoring the critical need for early detection, robust identity security measures, and meticulously tested recovery plans, alongside traditional endpoint protection.
Gunra Uses Stolen Sessions and RDP
A key characteristic of Gunra’s modus operandi is its preference for legitimate remote management tools and existing user accounts over custom, easily detectable malware. This approach allows them to blend seamlessly into network traffic, making their activities harder to pinpoint.
Initial Access and Lateral Movement
Upon gaining access to an administrator workstation, Gunra operators manipulate the SSL-VPN administration console. They specifically modify an inactive account, removing the requirement for a mandatory password change. This seemingly minor configuration alteration establishes a persistent and covert pathway between external and internal network segments, as detailed in a comprehensive analysis. The report highlights how crucial this seemingly minor step is.
From this foothold, stolen session data grants the attackers access to the internal virtual desktop infrastructure (VDI). They then utilize Remote Desktop Protocol (RDP) to reach critical internal systems, including the VDI authentication web server, the Active Directory server, and even the virtual desktops of IT personnel. This RDP-based pivot is particularly perilous because Active Directory serves as the central control for user accounts, devices, and permissions across many Windows networks. Compromising it allows attackers to map the entire environment, escalate privileges, and solidify their control. Previous incidents, such as a ransomware DCSync credential theft technique, illustrate how compromising directory replication can expose sensitive password data across an entire domain.
Gunra also employs Impacket tools over Server Message Block (SMB) and OpenSSH tunnels for lateral movement within compromised networks. On domain controllers, the group executes password-hash dumping tools to facilitate pass-the-hash and pass-the-ticket attacks. Furthermore, they modify VDI portal authentication files to ensure a chosen one-time password remains valid, effectively circumventing multi-factor authentication (MFA).
Data Theft Raises the Stakes
Before initiating encryption, Gunra affiliates utilize a specific executable to gather files from cloud storage services like OneDrive and SharePoint. These stolen files are then compressed and transferred to Mega, a cloud storage and file-sharing service. The use of common utilities such as archiving software, RClone, and FileZilla allows these exfiltration activities to blend in with legitimate administrative tasks, emphasizing the importance of behavior-based monitoring. One reported incident involving a Dubai hospital saw a staggering 40 terabytes of data exfiltrated. <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/3b80b578-1e1f-4993-a60d-06991a27197b/Gunra-Uses-Stolen-Sessions-and-RDP-to-Pivot-Into-Active-Directory-and-IT-Workstations.pdf?AWSAccessKeyId=ASIA2F3
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.