Cyber Security News

Gunra Uses Stolen Sessions and RDP to Pivot Into Active Directory and IT Workstations

Gunra ransomware has moved from a new name to a serious enterprise threat in a short time.

The group breaks into exposed edge devices, steals valuable data, and then encrypts systems across both Windows and Linux networks. The damage can spread quickly.

First observed in Windows environments in April 2025, Gunra later added a Linux variant and opened a ransomware-as-a-service program in January 2026.

The operation is linked to leaked Conti source code and uses double extortion: victims face locked files and threats that stolen material will be published or sold.

Analysts at Picus Security noted that Gunra affiliates exploit FortiOS and FortiProxy authentication bypasses, including CVE-2024-55591 and CVE-2025-24472, to establish administrator access.

Picus Security said in a report shared with Cyber Security News (CSN) that the campaign has targeted government, critical infrastructure, healthcare, finance, and nonprofit organizations worldwide.

Attackers collect documents, databases, personal information, and internal email before deploying the locker, with theft volumes reported in the tens of terabytes.

That makes early detection, identity security, and tested recovery plans as important as endpoint protection.

Gunra Uses Stolen Sessions and RDP

Gunra operators favor legitimate remote-management tools and existing accounts over noisy custom malware.

After reaching an administrator workstation, they accessed the SSL-VPN administration console and altered an unused account so it would not require a mandatory password change.

That small configuration change gave them a reliable route between external and internal networks.

From there, stolen session data gave the attackers entry to the internal virtual desktop infrastructure, or VDI.

They used Remote Desktop Protocol, commonly called RDP, to reach the VDI authentication web server, the Active Directory server, and IT employees’ virtual desktops.

Readers tracking how stolen RDP logins fuel attacks can see why this step is especially dangerous. Active Directory is the central directory that controls users, devices, and permissions in many Windows networks.

Reaching it can let intruders map the environment and expand their privileges.

In a related case, a ransomware DCSync credential theft technique showed how access to directory replication can expose password data across a domain.

Gunra also used Impacket tools over SMB, along with OpenSSH tunnels, to move between machines.

On compromised domain controllers, the group ran a password-hash dumping tool to support pass-the-hash and pass-the-ticket activity.

It also changed VDI portal authentication files so an attacker-selected one-time password would continue to work, undermining multi-factor authentication.

Data Theft Raises the Stakes

Before encryption, affiliates have used an executable to collect files from OneDrive and SharePoint, then compressed and transferred data to Mega.

Common utilities including archive software, RClone, and FileZilla can blend into normal administrative activity, making behavior-based monitoring important. One claimed theft from a Dubai hospital reached 40 terabytes.

Gunra then works quickly. Its Windows encryptor processes files in parallel with ChaCha20 and RSA-4096, adding a new extension and leaving a ransom note in affected directories.

The Linux version can use up to 100 threads and allows operators to select file types, encryption limits, and partial-encryption ratios, helping them tailor damage to the environment.

The attackers also try to weaken recovery by deleting volume shadow copies. In at least one reported incident, they removed backup and archived data at both primary and disaster-recovery sites before and after ransomware deployment.

That pattern mirrors why ransomware attacks exposed RDP services can become broader network compromises rather than single-host events.

Organizations should urgently patch affected FortiOS and FortiProxy systems, review administrator and VPN accounts, and invalidate suspicious sessions.

They should limit RDP to controlled access paths, require phishing-resistant MFA where possible, monitor unusual remote logins and directory activity, and protect backups with separate credentials and offline copies.

Guidance on a FortiOS bypass actively exploited also reinforces the need to apply vendor fixes promptly.

The organizations should validate whether their controls can detect and prevent the techniques used in Gunra intrusions.

Regular attack simulations and recovery exercises can reveal gaps before an attacker turns a stolen session into a domain-wide outage.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
Account nameforticloud-syncPersistent superuser account reportedly created through FortiOS and FortiProxy authentication bypass activity.
File namepsexec.pyImpacket script used for remote execution and lateral movement.
File namesmbclient.pyImpacket script used to access systems over SMB.
File namesecretsdump.pyImpacket script used to extract password hashes from domain controllers.
File namemain.exeExecutable used to collect files from OneDrive and SharePoint.
File nameR3ADM3.txtRansom note written into encrypted directories.
File extension.ENCRTExtension appended to files encrypted by Gunra.

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

2 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

2 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

3 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

4 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

4 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

5 hours ago