logo

APT Hackers Attacking RDP Servers to Deploy Malicious Payloads and Establish Persistence

ID: 840cc624-ff3a-5a60-b11d-6635d702d186

STIX ID: report--840cc624-ff3a-5a60-b11d-6635d702d186

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-03-24

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

APT-C-13 (aka Sandworm) is running a campaign (observed 2024–2026) that delivers a trojanized ISO ("Microsoft.Office.2025x64.v2025.iso") via Telegram/cracking communities to infect RDP-exposed hosts in critical infrastructure and government; installers (auto.exe/setup.exe) load a modular framework (Tambur/Kalambur/Sumbur/DemiMur) that establishes persistence through scheduled tasks in a fake Windows WDI path, tunnels RDP via SSH and Tor to hide C2, injects a forged root certificate, disables Defender protections, and enables months-long covert intelligence collection—recommendations include blocking unauthorized ISOs, monitoring scheduled tasks/registry/PowerShell activity, and creating detections for anomalous RDP/SSH behavior.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.