Separator

Sophos' Research on Remote Desktop Protocol Exposes Security Threats

Separator
Sophos' Research on Remote Desktop Protocol Exposes Security Threats

CEO Insights Team

Sophos, a cybersecurity company, publishes its latest research, ‘RDP Exposed: The Threat That’s Already at your Door’. This research on Remote Desktop Protocol (RDP) focuses on how the attackers find the RDP enabled devices as soon as it’s connected to the internet. During the research, Sophos deployed 10 geographically dispersed, low interaction honeypots to measure and analyse the RDP based risks. These honeypots were set-up in California, Frankfurt, Ireland, London, Mumbai, Ohio, Paris, Sao Paulo, Singapore, and Sydney for a period of 30 days. On an average, the RDP honeypots were attacked once every six seconds.

Since 2011, Sophos has been reporting on the cybercriminals for exploiting the RDP. Post that, the cybercriminals responsible for the Ransomware attacks, Matrix and SamSam have completely abandoned the network ingress towards the RDP. According to the study, nearly 4.3 million logins were attempted at a rate that gradually increased over the 30-day research period. The first honeypot was discovered in just one minute and 24 seconds in Paris and the last one was found in 15 hours in Singapore. Sophos’ research has found that the attackers use different strategies to crack the passwords. Among all the strategies, three main characteristics of the attack were named as the ram, the swarm and the hedgehog.

The ram is a strategy designed to uncover an administrator password. The report states, one attacker made 109,934 login attempts at the Irish honeypot, using just three usernames to gain the access.
The swarm attack is carried out using the sequential usernames and a finite number of the poor passwords. Lastly the hedgehog is characterised by bursts of activity followed by longer periods of inactivity.

This vulnerability is so serious it could be used to trigger a ransomware outbreak that could potentially spread around the world in hours



Matt Boddy, Security Specialist at Sophos states, “Most recently, a remote code execution flaw in RDP - nicknamed BlueKeep (CVE-2019-0708) - has been hitting the headlines. This vulnerability is so serious it could be used to trigger a ransomware outbreak that could potentially spread around the world in hours. However, securing against RDP threats goes far beyond patching systems against BlueKeep, which is just the tip of the iceberg. In addition to taking care of BlueKeep, IT managers need to pay broader attention to RDP overall because, as our Sophos research shows, cybercriminals are busy probing all potentially vulnerable computers exposed by RDP 24/7 with password guessing attacks.”

He further adds, “At present there are more than three million devices accessible via RDP worldwide, and it is now a preferred point of entry by cybercriminals. Sophos has been talking about how criminals deploying targeted ransomware like BitPaymer, Ryuk, Matrix, and SamSam have almost completely abandoned other methods used to break into an organization in favour of simply brute forcing RDP passwords. All of the honeypots were discovered within a few hours, just because they were exposed to the internet via RDP. The fundamental takeaway is to reduce the use of RDP wherever possible and ensure best password practice is in effect throughout an organization. Businesses need to act accordingly to put the right security protocol in place to protect against relentless attackers.”

In Print




Most Viewed

From 'Volume' to 'Value': India Inc's Mantra to Capture the Global Pharmaceutical Market A Fight Back from Arabian Peninsula When will The Tech Industry’s Lay-off Season End? The Story of a Broken Trust Technology Key To Global Travel Recovery What To Keep In Mind When Selecting The Right Air Compressor For Replacement? The Best Way to Recover from Ransomware Attacks How Tensions Grew Worse between Elon Musk and Donald Trump New Markets, New Brands: Tailoring Success for Different Places Empowered Leadership in a Changing Legal World Four Key Steps For Healthcare Providers To Combat Ransomware Turning Vision into Value: How I Built Purposeful Digital Ecosystems in the UK Dave Thomas: A Role Model for Aspiring Entrepreneurs, Philanthropists Digital Analytics Products: How Organizations Choose Them Kelly Ortberg: The New Boeing CEO Who is Already on the Headlines India’s Military Alacrity for Modern Threats Reshma Saujani: Reshaping Social Attitudes Around Gender and Tech India is Manifesting Leadership in Drone Technology 5 Greatest Role Models in the Manufacturing Industry Creating a Stronger Ecosystem by Fixing the Nuts & Bolts of the Economy Microsoft for India: Making India for Future Ready India's UPI Launch in France Opens Gateway to Global Fintech Power Tim Cook Nears Retirement, Who Will Take Over Apple's Throne? Soil Based Microbial Fuel Cells Could Protect the Environment from Flammable Chemicals The mantra of Academic Collaboration Echoes on this Teachers’ Day Indian semiconductor Boom Has Abundant Room for SME-preneurs Indian Healthcare Ecosystem is Hosting a Multidimensional Paradigm Shift Being a True Republic: You Got to Love this New, Powerful India Qatar World Cup 2022 Might Be Over, But Arabian Peninsula’s Sports Dream is Just Beginning Reimagining the UK–India Partnership in a Changing Global Order These Schemes Will Facilitate Women Entrepreneurs Decarbonization & Sustainable Future: Technology & What it can Do?


🍪 Do you like Cookies?

We use cookies to ensure you get the best experience. Read more…