Nowadays cybercriminals most actively exploiting Remote Desktop Protocol in order to gain access to the targeted victim’s computer and steal login credentials and other sensitive information.
Remote Desktop Protocol (RDP) is a proprietary network protocol that allows an individual to control the resources and data of a computer over the Internet
Threat actors Started exploiting RDP protocol since 2016 and compromised various targets around the world and used it to infect with malware and ransomware.
RDP protocol helps to provide complete control over the desktop of a remote machine by transmitting input such as mouse movements and keystrokes and sending back a graphical user interface.
In this case, username and password will be shared by both local and remote machine by mutual authentication in order to share both desktop access.
During the operation, attackers infiltrate the RDP connection of both machine and inject the malware or ransomware into the remote machine.
According to US-CERT, Cyber criminal selling stolen RDP access in various dark web underground marketplace.
These are following Ransomware attacks are the conducted by threat actors by infiltrating the RDP Protocol.
CrySiS Ransomware: CrySIS ransomware was distributed using open RDP Ports, brute-force and dictionary attacks to gain unauthorized remote access to the victim’s computer.
CryptON Ransomware: CryptON ransomware utilizes brute-force attacks to gain access to RDP sessions, then allows a threat actor to manually execute malicious programs on the compromised machine.
Samsam Ransomware: Samsam ransomware uses a wide range of exploits, including ones attacking RDP-enabled machines, to perform brute-force attacks.
In this case, Federal Bureau of Investigation (FBI) and Department of Homeland Security (DHS) warned to businesses to understand what remote accesses their networks allow and take steps to reduce the likelihood of compromise.
Troldesh Ransomware Spreading Via Weaponized Word Document and RDP Brute-force Attack
Critical Vulnerability with CredSSP Protocol Affects WinRM and RDP on all Windows Versions to Date
New Variant of Scarab Ransomware Distributed via RDP on Systems and Servers
Cybersecurity researcher "0xdf" has cracked the "Ghost" challenge on Hack The Box (HTB), a premier…
Google has unveiled Sec-Gemini v1, an AI model designed to redefine cybersecurity operations by empowering…
The United States has successfully extradited two Kosovo nationals, Ardit Kutleshi, 26, and Jetmir Kutleshi,…
Ivanti has issued an urgent security advisory for CVE-2025-22457, a critical vulnerability impacting Ivanti Connect…
A concerning malware campaign was disclosed by the AhnLab Security Intelligence Center (ASEC), revealing how…
EncryptHub, a rapidly evolving cybercriminal entity, has come under intense scrutiny following revelations of operational…