Indicators of RDP Brute Force Attacks
ID: d9bdbcec-e2b7-5555-9bd8-2c8004906d8f
STIX ID: report--d9bdbcec-e2b7-5555-9bd8-2c8004906d8f
Feed Name: WatchGuard Secplicity Blog
This report describes an incident in which two AWS EC2 Windows instances were compromised—likely via RDP brute-force—resulting in deployment of ransomware, cryptocurrency miners, and other malware; attackers performed successful logins, deleted Windows event logs, and changed domain credentials. The author observed widespread RDP login attempts from many IPs, lack of MFA, absent network firewall rules, and missing historical AWS logs; they recommend enabling CloudTrail and VPC Flow Logs, preserving time synchronization, and applying network and authentication protections to detect and prevent similar attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
