CYBERSECURITYTRACKER
TRACKING3,967 stories737 vuln stories
Permanent story citation

Hide Your RDP: Password Spray Leads to RansomHub Deployment

The story is preserved as cited. Later corrections remain visibly typed and adjacent to the original snapshot.

← newsStory 582

As cited

Citation snapshot as of .

ransomware

Hide Your RDP: Password Spray Leads to RansomHub Deployment

A password spray attack against an exposed RDP server in November 2024 led to RansomHub ransomware deployment. Threat actors used known malicious IP addresses to conduct multiple login attempts, eventually gaining access and deploying the ransomware payload.

Why it matters: Organizations running internet-facing RDP services are directly exposed to this attack vector; practitioners should immediately audit RDP accessibility, enforce strong credentials or multi-factor authentication, and monitor for brute force login attempts from known malicious sources.

Source published
First seen by Cybersecurity Tracker

Source attribution