Rogue RDP – Revisiting Initial Access Methods
ID: 7986b708-688c-544f-8f79-001b82df7ba4
STIX ID: report--7986b708-688c-544f-8f79-001b82df7ba4
Feed Name: Black Hills Infosec Blog
This post introduces “Rogue RDP,” a technique that weaponizes .RDP connection files in combination with a pyrdp MITM relay and a controlled RDP server to coerce victims into connecting with drive and clipboard redirection enabled, enabling file access, data exfiltration, and payload staging from the server side. It covers infrastructure setup, port/identity evasion (including signing .RDP files to reduce warnings), example attacks like binary planting and data theft via \tsclient paths, briefly notes potential RCE avenues, and recommends mitigations such as blocking .RDP attachments and hardening RDP redirection via Group Policy.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
