logo

Windows Remote Desktop Protocol: Remote to Rogue

ID: 9b80f19c-fec9-5f6a-8b96-6b2063ed08d6

STIX ID: report--9b80f19c-fec9-5f6a-8b96-6b2063ed08d6

Feed Name: Google Cloud Threat Intelligence

Threat Score
70/100

Date Published: 2025-04-07

Date Updated: 2026-04-27

Author: Google Threat Intelligence Group

...
...

This report analyzes malicious .rdp configuration files used in an espionage campaign attributed to UNC5837 that exploit RDP features (drive and clipboard redirection, RemoteApp) to grant attackers read/write access and present a deceptive application to victims, enabling potential file exfiltration and credential capture; it also discusses the likely use of RDP proxy tooling (e.g., PyRDP) and includes an observed .rdp sample SHA256.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.