CYBERSECURITYTRACKER
TRACKING7,811 stories in this site build1,697 vulnerability news stories in this site build
Permanent story citation

Hide Your RDP: Password Spray Leads to RansomHub Deployment

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 582

As cited

Copy frozen at (site build).

ransomware

Hide Your RDP: Password Spray Leads to RansomHub Deployment

A password spray attack against an exposed RDP server in November 2024 led to RansomHub ransomware deployment. Threat actors used known malicious IP addresses to conduct multiple login attempts, eventually gaining access and deploying the ransomware payload.

Why it matters: Organizations running internet-facing RDP services are directly exposed to this attack vector; practitioners should immediately audit RDP accessibility, enforce strong credentials or multi-factor authentication, and monitor for brute force login attempts from known malicious sources.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ransomware

Hide Your RDP: Password Spray Leads to RansomHub Deployment

A password spray attack against an exposed RDP server in November 2024 led to RansomHub ransomware deployment. Threat actors used known malicious IP addresses to conduct multiple login attempts, eventually gaining access and deploying the ransomware payload.

Why it matters: Organizations running internet-facing RDP services are directly exposed to this attack vector; practitioners should immediately audit RDP accessibility, enforce strong credentials or multi-factor authentication, and monitor for brute force login attempts from known malicious sources.

Actorsransomhub
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary