Gunra Uses Stolen Sessions and RDP to Pivot Into Active Directory and IT Workstations
Cybersecurity NewsArchived Aug 13, 2026✓ Full text saved
Gunra ransomware has moved from a new name to a serious enterprise threat in a short time. The group breaks into exposed edge devices, steals valuable data, and then encrypts systems across both Windows and Linux networks. The damage can spread quickly. First observed in Windows environments in April 2025, Gunra later added a Linux […] The post Gunra Uses Stolen Sessions and RDP to Pivot Into Active Directory and IT Workstations appeared first on Cyber Security News .
Full text archived locally
✦ AI Summary· Claude Sonnet
HomeCyber Security News
Gunra Uses Stolen Sessions and RDP to Pivot Into Active Directory and IT Workstations
By Tushar Subhra Dutta
August 13, 2026
Gunra ransomware has moved from a new name to a serious enterprise threat in a short time.
The group breaks into exposed edge devices, steals valuable data, and then encrypts systems across both Windows and Linux networks. The damage can spread quickly.
First observed in Windows environments in April 2025, Gunra later added a Linux variant and opened a ransomware-as-a-service program in January 2026.
The operation is linked to leaked Conti source code and uses double extortion: victims face locked files and threats that stolen material will be published or sold.
Analysts at Picus Security noted that Gunra affiliates exploit FortiOS and FortiProxy authentication bypasses, including CVE-2024-55591 and CVE-2025-24472, to establish administrator access.
Picus Security said in a report shared with Cyber Security News (CSN) that the campaign has targeted government, critical infrastructure, healthcare, finance, and nonprofit organizations worldwide.
Attackers collect documents, databases, personal information, and internal email before deploying the locker, with theft volumes reported in the tens of terabytes.
That makes early detection, identity security, and tested recovery plans as important as endpoint protection.
Gunra Uses Stolen Sessions and RDP
Gunra operators favor legitimate remote-management tools and existing accounts over noisy custom malware.
After reaching an administrator workstation, they accessed the SSL-VPN administration console and altered an unused account so it would not require a mandatory password change.
That small configuration change gave them a reliable route between external and internal networks.
From there, stolen session data gave the attackers entry to the internal virtual desktop infrastructure, or VDI.
They used Remote Desktop Protocol, commonly called RDP, to reach the VDI authentication web server, the Active Directory server, and IT employees’ virtual desktops.
Readers tracking how stolen RDP logins fuel attacks can see why this step is especially dangerous. Active Directory is the central directory that controls users, devices, and permissions in many Windows networks.
Reaching it can let intruders map the environment and expand their privileges.
In a related case, a ransomware DCSync credential theft technique showed how access to directory replication can expose password data across a domain.
Gunra also used Impacket tools over SMB, along with OpenSSH tunnels, to move between machines.
On compromised domain controllers, the group ran a password-hash dumping tool to support pass-the-hash and pass-the-ticket activity.
It also changed VDI portal authentication files so an attacker-selected one-time password would continue to work, undermining multi-factor authentication.
Data Theft Raises the Stakes
Before encryption, affiliates have used an executable to collect files from OneDrive and SharePoint, then compressed and transferred data to Mega.
Common utilities including archive software, RClone, and FileZilla can blend into normal administrative activity, making behavior-based monitoring important. One claimed theft from a Dubai hospital reached 40 terabytes.
Gunra then works quickly. Its Windows encryptor processes files in parallel with ChaCha20 and RSA-4096, adding a new extension and leaving a ransom note in affected directories.
The Linux version can use up to 100 threads and allows operators to select file types, encryption limits, and partial-encryption ratios, helping them tailor damage to the environment.
The attackers also try to weaken recovery by deleting volume shadow copies. In at least one reported incident, they removed backup and archived data at both primary and disaster-recovery sites before and after ransomware deployment.
That pattern mirrors why ransomware attacks exposed RDP services can become broader network compromises rather than single-host events.
Organizations should urgently patch affected FortiOS and FortiProxy systems, review administrator and VPN accounts, and invalidate suspicious sessions.
They should limit RDP to controlled access paths, require phishing-resistant MFA where possible, monitor unusual remote logins and directory activity, and protect backups with separate credentials and offline copies.
Guidance on a FortiOS bypass actively exploited also reinforces the need to apply vendor fixes promptly.
The organizations should validate whether their controls can detect and prevent the techniques used in Gunra intrusions.
Regular attack simulations and recovery exercises can reveal gaps before an attacker turns a stolen session into a domain-wide outage.
Indicators of compromise (IoCs):-
Type Indicator Description
Account name forticloud-sync Persistent superuser account reportedly created through FortiOS and FortiProxy authentication bypass activity.
File name psexec.py Impacket script used for remote execution and lateral movement.
File name smbclient.py Impacket script used to access systems over SMB.
File name secretsdump.py Impacket script used to extract password hashes from domain controllers.
File name main.exe Executable used to collect files from OneDrive and SharePoint.
File name R3ADM3.txt Ransom note written into encrypted directories.
File extension .ENCRT Extension appended to files encrypted by Gunra.
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world
Tags
cyber security
cyber security news
Copy URL
Linkedin
Twitter
ReddIt
Telegram
Tushar Subhra Dutta
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.
Cyber Security Guide
Top 10 Malware Threats of the Week – AsyncRAT, Remcos, and Xworm Lead the Surge
Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA
How Top SOCs Detect and Stop AI Phishing that Beats Email Gateways
Top 10 Phishing Kits Used by Hackers to Launch Cyberattacks (July 20-26, 2026)
An SOC Story of Why Fast Answers Beat Perfect Answers in Cyber Incident Response
Latest Cyber News
Cyber Security News
Wireshark 4.6.8 Released With Patch for 28 Vulnerabilities That Lead to Crashes
AI
Blacklight Toolkit Finds Codex, Claude Code, and Cursor Artifacts Exposing Tokens and Session Data
Cyber Security News
Phantom Stealer Hides Inside PNG Files, Then Steals Your Passwords, Cookies and Crypto
Cyber Security News
Trump Signs Memo Authorizing Private Firms for Cyber Operations Against Foreign Criminals
Adobe
Critical Adobe Commerce Vulnerabilities Allows Hackers to Execute Arbitrary Code
Expert Talks
Expert Talks
From Reactive Forensics to Predictive Defence: Strengthening Cyber Resilience in Banking
Expert Talks
Beyond the Lure: What the DoNot Campaign Reveals About Modern Cyber Espionage
Expert Talks
Your Incident Response Plan Has a Dependency You Never Approved
Expert Talks
Security in the AI Era Starts with First Principles
Cyber Security News
Planning Your AI Security – How will You Manage All Your Resources?