16,456,122 RDP Matches and 9,173,905 VNC Matches: The Remote Access Baseline
On 10 August 2026, CISA, the FBI, and partners warned that Gunra ransomware actors were targeting multiple critical infrastructure sectors. Ransomware operations depend on initial access, and remote access services are a common entry point. Two ZoomEye queries measured how much of that surface is exposed.
The RDP service query returned 16,456,122 matches. The VNC service query returned 9,173,905.
What the queries measured
Query 1: service="rdp"
Result: 16,456,122 matches
Search link: https://www.zoomeye.ai/searchResult?q=c2VydmljZT0icmRwIg%3D%3D
Query 2: service="vnc"
Result: 9,173,905 matches
Search link: https://www.zoomeye.ai/searchResult?q=c2VydmljZT0idm5jIg%3D%3D
Collection time: 23 September 2026, 02:34 UTC
Scope: all asset types, global
Why these numbers are large
RDP and VNC are remote desktop protocols. RDP is built into Windows and is widely used for administration. VNC is a cross-platform protocol used in both server and desktop environments, and it is common in industrial and embedded systems.
Both protocols are designed to be reached over a network, which means exposure is often intentional. A large count therefore does not indicate a large number of misconfigurations. It indicates how widely these services are deployed and reachable.
The ransomware connection
Ransomware operators use remote access services in two ways. They use them for initial access, through stolen credentials or brute force against an exposed service. They also use them for lateral movement, connecting to other systems once inside the network.
The Gunra advisory describes actors targeting multiple critical infrastructure sectors. For defenders, the relevant question is not the global count but which of their own remote access services are reachable from the internet and whether those services enforce strong authentication.
What to check
- Inventory every RDP and VNC service in your environment, including those on systems that are not part of the standard server fleet.
- Determine which of them are reachable from outside the network. A service that is reachable and uses password authentication is a brute-force target.
- Require multi-factor authentication for remote access where the protocol supports it, and use a gateway or jump host where it does not.
- Review authentication logs for failed attempts and for successful logins from unexpected sources.
- Disable or restrict VNC instances that are not actively managed, since VNC authentication is often weaker than RDP.
What the measurement does not show
The counts do not show authentication configuration, patch level, or which instances are reachable from the public internet versus a private network. A service match in ZoomEye indicates that the service was observed, not that it is exploitable. The numbers describe the scale of the protocol deployment, which is the context for evaluating your own exposure.
References
- CISA, "CISA, FBI and Partners Warn Organizations of Gunra Ransomware Actors Targeting Multiple Critical Infrastructure Sectors," 10 August 2026. https://www.cisa.gov/news-events/news/cisa-fbi-and-partners-warn-organizations-gunra-ransomware-actors-targeting-multiple-critical
- ZoomEye searches,
service="rdp"(16,456,122 matches) andservice="vnc"(9,173,905 matches), collected 23 September 2026.
Top comments (0)