Attacker enables RDP, creates admin, erases evidence in ten seconds
ID: 215c94c6-551a-54a0-b540-7872bc61a211
STIX ID: report--215c94c6-551a-54a0-b540-7872bc61a211
Feed Name: Heimdal Security Blog
A Heimdal incident report details a fast, living‑off‑the‑land intrusion on 2 June 2026 where an attacker authenticated via NTLMv2, programmatically enabled RDP, opened firewall port 3389, created a rogue admin account, and deleted artifacts — staging a ransomware deployment that reached 34 endpoints in under ten seconds; Heimdal XTP and REP detected correlated behavior and flagged ransomware-associated file activity. The report emphasizes NTLM relay/pass‑the‑hash as likely vectors, the limits of signature-based defenses and MFA for such attacks, recommended mitigations (SMB signing, reducing NTLM, removing standing admin rights, automation/isolation), and potential financial and regulatory impacts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
