Ransomware Delivered Using RDP Brute-Force Attack
ID: 728d9d2e-fde7-57ca-b588-bb7889911b83
STIX ID: report--728d9d2e-fde7-57ca-b588-bb7889911b83
Feed Name: Zscaler Security Research Blog
This report analyzes Dharma (Crysis) ransomware spread via exposed RDP services and brute-force access, detailing the infection chain (port scanning, credential access, backup deletion, payload deployment), technical behaviors (vssadmin shadow deletion, AES-256 + RSA-1024 encryption, file naming pattern, ransom notes), persistence and lateral movement techniques (copying to Startup/Run keys, use of Mimikatz and credential theft, potential GPO abuse), and recommended mitigations such as removing RDP from public exposure, enforcing strong passwords, and adopting zero-trust access controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
