logo

Indicators of RDP Brute Force Attacks

ID: d9bdbcec-e2b7-5555-9bd8-2c8004906d8f

STIX ID: report--d9bdbcec-e2b7-5555-9bd8-2c8004906d8f

Feed Name: WatchGuard Secplicity Blog

Threat Score
70/100

Date Published: 2017-12-05

Date Updated: 2026-05-01

Author: The Editor

...
...

This report describes an incident in which two AWS EC2 Windows instances were compromised—likely via RDP brute-force—resulting in deployment of ransomware, cryptocurrency miners, and other malware; attackers performed successful logins, deleted Windows event logs, and changed domain credentials. The author observed widespread RDP login attempts from many IPs, lack of MFA, absent network firewall rules, and missing historical AWS logs; they recommend enabling CloudTrail and VPC Flow Logs, preserving time synchronization, and applying network and authentication protections to detect and prevent similar attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.