Monday, April 14, 2025
Homecyber securityRDP Servers Hacked To Deploy Ransomware and Steal Sensitive Data

RDP Servers Hacked To Deploy Ransomware and Steal Sensitive Data

Published on

SIEM as a Service

Follow Us on Google News

Research carried out by security analysts at CRIL (Cyble Research and Intelligence Labs) recently identified several ransomware groups that are actively targeting open RDP ports in an attempt to deploy ransomware.

There could be major security issues that could occur if an RDP port is left open on the internet without being protected. Systems with exposed RDP ports can be easily located by threat actors by scanning the internet. 

After that, using either stolen credentials or vulnerabilities, attackers can easily gain access to vulnerable systems by exploiting those exposed RDP ports.

- Advertisement - Google News

CISA reports that some ransomware groups have accessed victims’ devices by using vulnerable RDP configurations, with the goal of encrypting their data and holding it hostage, in the process. Among those ransomware groups, we have mentioned a few of them:-

  • Daixin Team
  • MedusaLocker

Analysis

Research has discovered that during the course of their analysis that to launch ransomware attacks, threat actors are still actively using exposed Remote Desktop services.

Cyble Global Sensor Intelligence (CGSI) reports that over a 3-month time frame, there have been more than 4,783,842 exploitation attempts made by threat actors from several ransomware groups, peaking at the following intervals in terms of the number of attempts:-

  • September end
  • Mid-November

More than 18 instances indicating a ransomware incident were identified through one of the online scanners of Cyble. A majority of these instances originate from the following countries:- 

  • The United States of America (US)
  • The Russian Federation (RU)

Apart from these two countries, there are others who joined this list, and here they are:-

  • South Korea
  • Netherlands
  • India
  • Vietnam

These data make it easier for anyone to obtain a clear understanding of the vulnerabilities and vulnerable versions that were used by threat actors to gain access to the network of a victim organization.

Instances affected by the BlueKeep (CVE-2019-0708) vulnerability still exist on the Internet, with over 50,000 instances still exposed.

Throughout darkweb forums, more than 154 posts by various threat actors were identified offering illicit RDP access to a large number of critical infrastructure sectors such as:-

  • Government
  • LEA
  • BFSI
  • Manufacturing
  • Telecommunications

Ransomware families found

In addition to the analysis provided by Cyble Researchers, five ransomware families have been identified, that target open RDP ports at this time.

Here below we have mentioned all the ransomware families detected:

  • Redeemer

Redeemer ransomware is a C/C++-based binary that targets windows operation systems.

  • NYX

NYX ransomware surfaced in 2022. It’s developed in C/C++. This ransomware is possibly based on Conti ransomware. 

  • Vohuk And Amelia

Researchers spotted these two ransomware groups targeting open RDP ports. Two ransomware groups might have originated from the same source

  • BlackHunt

BlackHunt is a new ransomware that was spotted targeting open RDP ports recently. A ransom note named “ReadMe” gives instructions for decrypting the file

Especially in the case of supply chains, ransomware attacks have caused a great deal of damage. A shortage of critical infrastructure services has a negative impact on the public and state entities that are dependent on their availability for their daily operations.

Recommendations

A proactive approach must be taken by organizations dealing with critical infrastructure in order to prevent ransomware attacks from taking place.

Here below we have mentioned the recommendations offered by the security experts:-

  • Make sure that outdated applications and devices are patched.
  • Segment the network properly and implement the appropriate security measures.
  • Utilize software bills of materials to increase the visibility of assets.
  • Maintain a well-configured and updated firewall.
  • Ensure that open ports that are not being managed by the administrator are closed.
  • An audit and VAPT exercise should be performed on a regular basis.
  • Monitoring and logging of assets should be performed in a proper manner.
  • Ensure that the organization implements proper access controls.
  • The organization should implement a cyber security awareness program for its employees.
  • Make sure that the organization follows a strong password policy.

Secure Web Gateway – Web Filter Rules, Activity Tracking & Malware Protection – Download Free E-Book

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Slow Pisces Group Targets Developers Using Coding Challenges Laced with Python Malware

A North Korean state-sponsored threat group known as "Slow Pisces" has been orchestrating sophisticated...

DoJ Launches Critical National Security Program to Protect Americans’ Sensitive Data

The U.S. Department of Justice has launched a landmark initiative to block foreign adversaries—including...

FortiGate 0-Day Exploit Allegedly Up for Sale on Dark Web

A chilling new development in the cybersecurity landscape has emerged, as a threat actor...

Alleged FUD Malware ‘GYware’ Advertised on Hacker Forum for $35/Month

A new Remote Access Trojan (RAT) known as "GYware" is being marketed on a...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Slow Pisces Group Targets Developers Using Coding Challenges Laced with Python Malware

A North Korean state-sponsored threat group known as "Slow Pisces" has been orchestrating sophisticated...

DoJ Launches Critical National Security Program to Protect Americans’ Sensitive Data

The U.S. Department of Justice has launched a landmark initiative to block foreign adversaries—including...

FortiGate 0-Day Exploit Allegedly Up for Sale on Dark Web

A chilling new development in the cybersecurity landscape has emerged, as a threat actor...