Internet-Exposed RDP Is Still the Ransomware On-Ramp the Gunra Advisory Warns About
The Gunra ransomware advisory published on 10 August 2026 lists three key actions for defenders. The first is to prioritise patching known exploited vulnerabilities in internet-facing systems, and it names virtual private network gateways and RDP-exposed infrastructure in the same breath [1]. The pairing is deliberate. Remote Desktop Protocol remains one of the shortest paths from the public internet into an internal network.
What the advisory actually records
The advisory maps Gunra's initial access to the exploitation of known vulnerabilities in internet-facing devices, including firewall and VPN appliances, and cites two FortiOS and FortiProxy authentication bypass issues, CVE-2024-55591 and CVE-2025-24472 [1]. Its description of lateral movement is equally concrete: actors used Impacket's psexec.py and smbclient.py to move across victim networks over Server Message Block, and in one intrusion they reached an internal virtual desktop infrastructure environment and continued lateral movement over RDP [1].
Read that sequence as a chain rather than a list. An affiliate needs one usable entry point and one protocol to move outward from it. RDP serves both purposes when it is published to the internet, because the same service that admits a legitimate administrator also admits anyone holding or guessing a credential.
Size of the externally reachable population
ZoomEye observations collected on 28 September 2026 give a sense of scale for the exposed RDP population [2]:
| Query | ZoomEye matches (28 Sep 2026) |
|---|---|
| service="rdp" | 16,471,930 |
| port="3389" && service="rdp" | 15,686,374 |
| service="rdp" && country="US" | 3,353,836 |
| service="vnc" | 9,190,464 |
The gap between the first two rows is instructive. A service-fingerprint query returned roughly 16.47 million matches, while adding an explicit port condition returned approximately 15.69 million. The difference of several hundred thousand endpoints reflects hosts where the protocol was identified on a non-standard port, or where the fingerprint and the port record disagree. Treating RDP exposure as equivalent to port 3389 therefore undercounts, and it hides services running where no one expected them.
These figures describe observable, fingerprint-matched endpoints. They do not establish that any particular host is unpatched, has a weak credential, or has been accessed by a Gunra affiliate. They measure how large the searchable population is, not how many organisations are affected.
Reading the geography filter honestly
Narrowing to a single country reduces the count substantially. The United States slice of service="rdp" returned 3,353,836 matches on the same date [2]. That narrowing is useful for prioritisation, but it inherits every limitation of IP geolocation, including hosting providers, content delivery infrastructure and misattribution. A country filter is a heuristic for triage, not a statement about ownership or jurisdiction.
A practical reduction programme
The advisory's recommended mitigations are engineering tasks rather than policy statements. For exposed RDP specifically:
- Remove direct internet exposure. Remote operational access should pass through a VPN or gateway device rather than terminating on the endpoint [1].
- Enforce account lockout. One documented Gunra intrusion used an SSL-VPN appliance administrator account reached through default credentials where account lockout controls were absent [1].
- Segment networks so that a compromised workstation cannot reach every other system, which is the mitigation the advisory lists for limiting lateral movement [1].
- Keep an offline, immutable backup stored in a physically separate, segmented location, so that recovery does not depend on a ransom payment [1]. Each of these is verifiable. Exposure reduction can be confirmed externally; lockout policy and segmentation can be confirmed by configuration review; backup immutability can be confirmed by attempting a restore.
Where external measurement helps
A periodic ZoomEye query for the remote-access protocols an organisation actually uses produces a dated external view that internal scanning cannot replicate. It catches the forgotten lab machine, the integrator-managed appliance and the departmental service that never entered the register. Used alongside, never instead of, configuration review, it turns the advisory's first key action into a measurable, repeating control.
Practical next steps
Pull the current list of externally reachable remote-access services, confirm each one's owner and business justification, and remove exposure that cannot be justified. For what remains, verify lockout, MFA and authentication logging, and confirm that a tested offline backup exists.
References
[1] Cybersecurity and Infrastructure Security Agency et al., "#StopRansomware: Gunra Ransomware", advisory AA26-222A, 10 August 2026. https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-222a
[2] ZoomEye, external asset queries collected on 28 September 2026. https://www.zoomeye.ai/
[3] MITRE ATT&CK, Enterprise matrix, version 19.1. https://attack.mitre.org/
Top comments (0)