logo

Ransomware Delivered Using RDP Brute-Force Attack

ID: 728d9d2e-fde7-57ca-b588-bb7889911b83

STIX ID: report--728d9d2e-fde7-57ca-b588-bb7889911b83

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report analyzes Dharma (Crysis) ransomware spread via exposed RDP services and brute-force access, detailing the infection chain (port scanning, credential access, backup deletion, payload deployment), technical behaviors (vssadmin shadow deletion, AES-256 + RSA-1024 encryption, file naming pattern, ransom notes), persistence and lateral movement techniques (copying to Startup/Run keys, use of Mimikatz and credential theft, potential GPO abuse), and recommended mitigations such as removing RDP from public exposure, enforcing strong passwords, and adopting zero-trust access controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.