logo

Windows Remote Desktop Leaves Behind Image Fragments Attackers Can Stitch Into Screenshots

ID: 8973f707-57b4-5933-ba3c-8836731a559b

STIX ID: report--8973f707-57b4-5933-ba3c-8836731a559b

Feed Name: cybersecurityNews.com

Threat Score
65/100

Date Published: 2026-04-28

Date Updated: 2026-04-28

Author: Guru Baran

...
...

This report warns that Windows' RDP Bitmap Cache saves small image tiles of remote sessions to disk that attackers can compress, exfiltrate, and reconstruct into readable screenshots using free tools (e.g., bmc-tools and RdpCacheStitcher). The write-up describes the attack sequence (locating the cache in user AppData, zipping via PowerShell, exfiltrating over HTTPS, deleting traces), notes threat groups that exploit RDP access, and recommends mitigations such as disabling the cache via Group Policy, monitoring access to the RDP cache folder, alerting on PowerShell compression and outbound HTTPS of archives, and adding cache checks to IR playbooks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.