Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Gunra ransomware: what identity and lateral movement controls are missing


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15509
Topic starter  

TL;DR: Gunra ransomware combines Fortinet exploitation, NTDS credential dumping, pass-the-hash movement, and Shadow Copy deletion, while SafeBreach maps the campaign to ATT&CK simulations and CISA Alert AA26-222A guidance. The lesson is that perimeter compromise quickly turns into identity abuse unless privileged access, detection, and recovery controls are validated together.

NHIMG editorial — based on content published by SafeBreach covering the Gunra ransomware CISA alert: Gunra Ransomware: SafeBreach Coverage for CISA Alert AA26-222A

Questions worth separating out

Q: What breaks when attackers can dump domain credentials and replay them laterally?

A: When attackers can dump domain credentials and replay them, the environment loses the distinction between an authenticated user and a trusted attacker.

Q: Why do exposed VPN and firewall appliances create ransomware blast radius problems?

A: Exposed VPN and firewall appliances often sit at the junction of remote access and administrative trust, so compromise there gives attackers both connectivity and identity leverage.

Q: How should security teams limit ransomware spread through identity controls?

A: Security teams should reduce standing privilege, segment admin roles, and require task-scoped elevation for high-risk actions.

Practitioner guidance

  • Harden edge-device identities Inventory firewall and VPN appliance accounts, disable unused administrative identities, and alert on new super-user creation such as unexpected device-local admin accounts.
  • Break credential replay paths Prioritise domain controller protection, Kerberos and NTLM hardening, and rapid revocation of hashes, tickets, and stored passwords that can be reused laterally.
  • Separate recovery access from production access Place backup deletion, shadow copy management, and disaster recovery permissions under distinct accounts with tight monitoring and no standing elevation.

What's in the full article

SafeBreach's full analysis covers the operational detail this post intentionally leaves for the source:

  • ATT&CK-mapped simulation IDs for NTDS dumping, pass-the-hash, shadow copy deletion, and SharePoint exfiltration.
  • CISA advisory IOC handling guidance, including how to use the supplied indicators without overblocking historical infrastructure.
  • Detailed mitigation steps for Fortinet compromise indicators, recovery inhibition, and off-hours privileged activity.
  • Platform workflow guidance for running the AA26-222A scenarios and filtering related attack playbooks.

👉 Read SafeBreach's analysis of Gunra ransomware and CISA Alert AA26-222A →

Gunra ransomware: what identity and lateral movement controls are missing?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 15094
 

Identity compromise is now the fastest route from edge exposure to ransomware impact. Gunra shows that a firewall or VPN compromise is not a network event in isolation. Once administrative access or reused credentials are available, the attacker is operating inside the identity plane, where privilege, session reuse, and off-boarded access gaps determine blast radius. For practitioners, the lesson is to govern edge appliances as identity-bearing systems, not just perimeter devices.

A few things that frame the scale:

A question worth separating out:

Q: Who is accountable when recovery controls fail during a double-extortion attack?

A: Accountability sits with the owners of identity, backup, infrastructure, and incident response controls because double extortion exploits the overlap between them. If recovery permissions, backup isolation, or log retention are not clearly assigned, attackers can erase evidence and reduce recovery options. Governance must define who owns each recovery identity and who reviews it.

👉 Read our full editorial: Gunra ransomware alerts show identity controls still fail at the edge



   
ReplyQuote
Share: