Gunra Uses Stolen Sessions and RDP to Pivot Into Active Directory and IT Workstations
Brief
Gunra ransomware has moved from a new name to a serious enterprise threat in a short time.
The group breaks into exposed edge devices, steals valuable data, and then encrypts systems across both Windows and Linux networks. The damage can spread quickly.
First observed in Windows environments in April 2025, Gunra later added a Linux variant and opened a ransomware-as-a-service program in January 2026.
The operation is linked to leaked Conti source code and uses double extortion: victims face locked files and threats that stolen material will be published or sold.
Analysts at Picus Security noted that Gunra affiliates exploit FortiOS and FortiProxy authentication bypasses, including CVE-2024-55591 and CVE-2025-24472, to establish administrator access.
