logo

BlueKeep Attack Detected by AhnLab EDR

ID: fb60bb4b-67fc-5965-b01f-5099783fd504

STIX ID: report--fb60bb4b-67fc-5965-b01f-5099783fd504

Feed Name: ASEC

Threat Score
70/100

Date Published: 2024-10-23

Date Updated: 2026-04-26

Author: ATCP

...
...

This report details active exploitation of the BlueKeep (CVE-2019-0708) RDP vulnerability observed by AhnLab EDR: attackers deliver RCE via the MS_T120 channel and then abuse Windows accessibility features (renaming cmd.exe to Narrator.exe) to run cmd.exe as SYSTEM for privilege escalation. The post links the observed activity to previously described BlueKeep tooling and highlights EDR-detected malicious commands and behavior, emphasizing endpoint monitoring and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.