Internet-Exposed RDP Is Still the Ransomware On-Ramp the Gunra Advisory Warns About
Internet-Exposed RDP Is Still the Ransomware On-Ramp the Gunra Advisory Warns About The Gunra ransomware advisory published on 10 August 2026 lists three key actions for defenders. The first is to prioritise patching known exploited vulnerabilities in internet-facing systems, and it names virtual private network gateways and RDP-exposed infrastructure in the same breath [1]. The pairing is…
The Gunra ransomware advisory issued on August 10, 2026, identifies internet-exposed Remote Desktop Protocol (RDP) as the primary entry point for ransomware attacks. The advisory warns that prioritising patching vulnerable systems is crucial, specifically mentioning virtual private network (VPN) gateways and RDP-exposed infrastructure.
Gunra's initial access often involves exploiting known vulnerabilities in internet-facing devices, such as firewall and VPN appliances (CVE-2024-55591 and CVE-2025-24472). Once inside, attackers use tools like Impacket's psexec.py and smbclient.py to move laterally across networks using the Server Message Block (SMB) protocol, and in some cases, they gain access to internal virtual desktop infrastructure environments via RDP.
The advisory highlights that RDP, when exposed to the internet, serves as both an entry point and a means for lateral movement within a network due to its ability to admit legitimate administrators and attackers alike. While ZoomEye observations show a vast number of exposed RDP endpoints globally, the advisory cautions that this number does not necessarily indicate the actual number of affected systems, as many factors can influence exposure status.
The advisory recommends several practical mitigation steps, including removing direct internet exposure of RDP, enforcing account lockout policies, segmenting networks to limit lateral movement, and maintaining offline, immutable backups that are stored separately from the active network. Additionally, periodic external queries using tools like ZoomEye can help identify forgotten or unmonitored remote-access services, providing a more accurate representation of an organisation's exposure risk.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.