logo

Cybercriminals Actively Exploiting RDP to Target Remote Organizations

ID: bf3ff334-1a83-531f-b524-3fa751b2db41

STIX ID: report--bf3ff334-1a83-531f-b524-3fa751b2db41

Feed Name: McAfee Labs Blog

Threat Score
70/100

Date Published: 2020-05-07

Date Updated: 2026-04-28

Author: Thomas Roccia

...
...

This McAfee ATR blog summarizes a sharp increase in Internet-exposed RDP services and the associated risks: attackers are exploiting weak passwords, protocol vulnerabilities (e.g., BlueKeep and Remote Desktop Gateway issues), and underground markets selling RDP access to perform spam, malware distribution, and network compromise; the post provides defensive guidance such as avoiding direct Internet-facing RDP, using MFA, patching, and restricting administrative access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.