logo

Attacker enables RDP, creates admin, erases evidence in ten seconds

ID: 215c94c6-551a-54a0-b540-7872bc61a211

STIX ID: report--215c94c6-551a-54a0-b540-7872bc61a211

Feed Name: Heimdal Security Blog

Threat Score
78/100

Date Published: 2026-06-22

Date Updated: 2026-06-22

Author: Danny Mitchell

...
...

A Heimdal incident report details a fast, living‑off‑the‑land intrusion on 2 June 2026 where an attacker authenticated via NTLMv2, programmatically enabled RDP, opened firewall port 3389, created a rogue admin account, and deleted artifacts — staging a ransomware deployment that reached 34 endpoints in under ten seconds; Heimdal XTP and REP detected correlated behavior and flagged ransomware-associated file activity. The report emphasizes NTLM relay/pass‑the‑hash as likely vectors, the limits of signature-based defenses and MFA for such attacks, recommended mitigations (SMB signing, reducing NTLM, removing standing admin rights, automation/isolation), and potential financial and regulatory impacts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.