logo

RDP and VPN Remain Top Ransomware Attack Pathways

ID: e8b964c6-4eee-5672-ad91-8fd8499d87c3

STIX ID: report--e8b964c6-4eee-5672-ad91-8fd8499d87c3

Feed Name: Halcyon Blog

Threat Score
75/100

Date Published: 2025-03-14

Date Updated: 2026-04-28

...
...

**Executive summary:** Analysis of Black Basta chat logs and related reporting shows the group leveraged nearly 3,000 unique credentials to infiltrate corporate networks via exposed VPN and remote-desktop/web-access portals (e.g., Microsoft RD Web, Palo Alto GlobalProtect, Cisco VPN), enabling data theft and ransomware deployment; the report highlights widespread exposed login panels, common ransomware TTPs (credential spraying, MFA bypass, lateral movement, supply-chain exploitation such as Kaseya), and recommends securing remote access, enforcing MFA, timely patching, and continuous monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.