logo

Ransomware deployments after brute force RDP attack

ID: 80eb86de-5a77-5a2d-9100-26d9f561988b

STIX ID: report--80eb86de-5a77-5a2d-9100-26d9f561988b

Feed Name: Fox-IT blog

Threat Score
75/100

Date Published: 2016-05-02

Date Updated: 2026-04-27

Author: Wouter Jansen

...
...

Fox-IT documents multiple incidents in which attackers brute-forced internet-exposed Remote Desktop Protocol (RDP) servers to gain access, perform prolonged reconnaissance and lateral movement, and ultimately deploy ransomware from compromised servers; this approach increases impact by targeting servers and backups and leads to negotiated, potentially large ransoms. The report explains infection vectors (spam, malvertising, exploit kits, and compromised RDP), impact on networks and backups, and provides concrete prevention, detection and response guidance such as disabling internet-facing RDP, enforcing strong passwords/2FA, secure logging, 24/7 monitoring and engaging incident response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.