Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Microsoft SharePoint CVE-2023-29357 Actively Exploited
August 13, 2026
Cloudflare Reports Record DDoS Attacks Exceeding 1 Tbps in H1 2023
August 13, 2026
Gunra Attackers Hijack RDP Sessions to Compromise Active Directory
August 13, 2026
Home/CyberSecurity News/Gunra Attackers Hijack RDP Sessions to Compromise Active Directory
CyberSecurity News

Gunra Attackers Hijack RDP Sessions to Compromise Active Directory

Key Takeaways The Gunra ransomware group has rapidly escalated into a significant threat, targeting critical sectors globally. Attackers exploit authentication bypass vulnerabilities in FortiOS and...

Jennifer sherman
Jennifer sherman
August 13, 2026 3 Min Read
2 0

Key Takeaways

  • The Gunra ransomware group has rapidly escalated into a significant threat, targeting critical sectors globally.
  • Attackers exploit authentication bypass vulnerabilities in FortiOS and FortiProxy (CVE-2024-55591, CVE-2025-24472) to gain initial access.
  • The group leverages stolen RDP sessions and legitimate remote management tools to compromise Active Directory and IT workstations, facilitating widespread network encryption.
  • Gunra employs a double extortion model, exfiltrating terabytes of sensitive data before encrypting systems on both Windows and Linux networks.
  • Effective mitigation requires urgent patching, robust identity security, vigilant monitoring of remote access, and comprehensive backup strategies.

The Gunra ransomware operation has quickly evolved from a nascent threat to a formidable force targeting enterprises worldwide, according to recent analysis. This sophisticated group not only encrypts systems across Windows and Linux environments but also engages in extensive data exfiltration, posing a severe double extortion risk to its victims.

Table Of Content

  • Key Takeaways
  • Gunra Uses Stolen Sessions and RDP
  • Initial Access and Lateral Movement
  • Data Theft Raises the Stakes

Initially identified in Windows systems in April 2025, Gunra expanded its capabilities with a Linux variant and launched a ransomware-as-a-service (RaaS) program by January 2026. The group’s tactics bear a resemblance to the leaked Conti source code, employing a dual approach of locking down victim files and threatening to publish or sell stolen data.

Analysts at Picus Security have detailed how Gunra affiliates exploit critical authentication bypass vulnerabilities in FortiOS and FortiProxy, specifically CVE-2024-55591 and CVE-2025-24472, to achieve elevated administrative access. In a report shared with Cyber Security News (CSN), Picus Security highlighted that the campaign has indiscriminately targeted government entities, critical infrastructure, healthcare providers, financial institutions, and nonprofit organizations across the globe.

Before deploying their ransomware, attackers systematically collect vast quantities of sensitive information, including documents, databases, personal records, and internal emails. Reported data theft volumes have reached tens of terabytes, underscoring the critical need for early detection, robust identity security measures, and meticulously tested recovery plans, alongside traditional endpoint protection.

Gunra Uses Stolen Sessions and RDP

A key characteristic of Gunra’s modus operandi is its preference for legitimate remote management tools and existing user accounts over custom, easily detectable malware. This approach allows them to blend seamlessly into network traffic, making their activities harder to pinpoint.

Initial Access and Lateral Movement

Upon gaining access to an administrator workstation, Gunra operators manipulate the SSL-VPN administration console. They specifically modify an inactive account, removing the requirement for a mandatory password change. This seemingly minor configuration alteration establishes a persistent and covert pathway between external and internal network segments, as detailed in a comprehensive analysis. The report highlights how crucial this seemingly minor step is.

From this foothold, stolen session data grants the attackers access to the internal virtual desktop infrastructure (VDI). They then utilize Remote Desktop Protocol (RDP) to reach critical internal systems, including the VDI authentication web server, the Active Directory server, and even the virtual desktops of IT personnel. This RDP-based pivot is particularly perilous because Active Directory serves as the central control for user accounts, devices, and permissions across many Windows networks. Compromising it allows attackers to map the entire environment, escalate privileges, and solidify their control. Previous incidents, such as a ransomware DCSync credential theft technique, illustrate how compromising directory replication can expose sensitive password data across an entire domain.

Gunra also employs Impacket tools over Server Message Block (SMB) and OpenSSH tunnels for lateral movement within compromised networks. On domain controllers, the group executes password-hash dumping tools to facilitate pass-the-hash and pass-the-ticket attacks. Furthermore, they modify VDI portal authentication files to ensure a chosen one-time password remains valid, effectively circumventing multi-factor authentication (MFA).

Data Theft Raises the Stakes

Before initiating encryption, Gunra affiliates utilize a specific executable to gather files from cloud storage services like OneDrive and SharePoint. These stolen files are then compressed and transferred to Mega, a cloud storage and file-sharing service. The use of common utilities such as archiving software, RClone, and FileZilla allows these exfiltration activities to blend in with legitimate administrative tasks, emphasizing the importance of behavior-based monitoring. One reported incident involving a Dubai hospital saw a staggering 40 terabytes of data exfiltrated. <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/3b80b578-1e1f-4993-a60d-06991a27197b/Gunra-Uses-Stolen-Sessions-and-RDP-to-Pivot-Into-Active-Directory-and-IT-Workstations.pdf?AWSAccessKeyId=ASIA2F3

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitMalwarePatchphishingransomwareSecurityThreat

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

LiteLLM Critical Flaw Exposes Cloud Keys and CI/CD Secrets from 2,488 Companies

Next Post

Cloudflare Reports Record DDoS Attacks Exceeding 1 Tbps in H1 2023

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Phantom Stealer Malware Hides in PNGs to Steal Credentials
August 13, 2026
Blacklight Toolkit Exposes Tokens, Session Data in Codex, Claude, Cursor Artifacts
August 13, 2026
Trump Authorizes Private Firms for Cyber Operations Against Foreign Criminals
August 13, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us