Mapping MITRE ATT&CK to Compromised RDP Sales
ID: daa88b29-c829-546e-a293-9b81e476a2fd
STIX ID: report--daa88b29-c829-546e-a293-9b81e476a2fd
Feed Name: ReliaQuest Blog
ReliaQuest analyzed over 500 cybercriminal forum listings in 2020 and found compromised Remote Desktop Protocol (RDP) servers to be the predominant initial access commodity sold by Initial Access Brokers (IABs). The report maps RDP exploitation techniques to MITRE ATT&CK (reconnaissance, external remote services, valid accounts, exploitation of remote services, and impact), highlights RDP-driven ransomware and DDoS risks, and recommends mitigations such as strong passwords, multi-factor authentication, attack-surface monitoring, and CTI-driven exposure tracking.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
