As cited
Citation snapshot as of .
ransomware
Hide Your RDP: Password Spray Leads to RansomHub Deployment
A password spray attack against an exposed RDP server in November 2024 led to RansomHub ransomware deployment. Threat actors used known malicious IP addresses to conduct multiple login attempts, eventually gaining access and deploying the ransomware payload.
Why it matters: Organizations running internet-facing RDP services are directly exposed to this attack vector; practitioners should immediately audit RDP accessibility, enforce strong credentials or multi-factor authentication, and monitor for brute force login attempts from known malicious sources.
- Source published
- First seen by Cybersecurity Tracker