{"id":46,"date":"2018-09-28T14:23:37","date_gmt":"2018-09-28T14:23:37","guid":{"rendered":"https:\/\/cms.digitalbes.com\/?p=46"},"modified":"2018-09-28T14:23:37","modified_gmt":"2018-09-28T14:23:37","slug":"fbi-warns-companies-about-hackers-increasingly-abusing-rdp","status":"publish","type":"post","link":"https:\/\/cms.digitalbes.com\/?p=46","title":{"rendered":"FBI warns companies about hackers increasingly abusing RDP"},"content":{"rendered":"<p>FBI warns companies about hackers increasingly abusing RDP connections. Not too many of us knows the full meaning of RDP so, we are going to explain it in a brief for you to understand what this warning is all about.<\/p>\n<p>RDP is an acronym which means remote desktop protocol and is a proprietary protocol developed by Microsoft, which provides a user with a graphical interface to connect to another computer over a network connection. The user employs\u00a0RDP\u00a0client software for this purpose, while the other computer must run\u00a0RDP\u00a0server software.<\/p>\n<p>In a public service announcement published on the 27th of September 2018 by the US Federal Bureau of Investigation\u2019s (FBI) Internet Crime Complaint Center (IC3), the FBI is warning companies about the dangers of leaving RDP endpoints exposed online.<\/p>\n<p>RDP stands for the Remote Desktop Protocol, a proprietary technology developed by Microsoft in the 90s that allows a user to log into a remote computer and interact with its OS via a visual interface that includes mouse and keyboard input \u2013hence the name \u201cremote desktop.\u201d<\/p>\n<p>RDP access is rarely enabled on home computers, but it\u2019s often turned on for workstations in enterprise networks or for computers located in remote locations, where system administrators need access to, but can\u2019t get to in person.<\/p>\n<p>In its\u00a0alert, the FBI mentions that the number of computers with an RDP connection left accessible on the Internet has gone up since mid and late 2016.<\/p>\n<p>This assertion from the FBI correlates with numbers and trends reported by cyber-security firms in the past few years. For example, just one company, Rapid7, reported seeing nine million devices with port 3389 (RDP) enabled on the Internet in early 2016, and that number rose to\u00a0over 11 million by mid-to-late 2017.<\/p>\n<p>Hackers, too, read cyber-security reports. Early warnings from the private sector about the increasing number of RDP endpoints caught hackers\u2019 attention long before sysadmins.<\/p>\n<p>For the past few years, there has been a constant stream of incident reports in which investigators found that hackers got an initial foothold on victims\u2019 networks thanks via a computer with an exposed RDP connection.<\/p>\n<p>Nowhere has this been more the case than in ransomware attacks. Over the past three years, there have been tens of ransomware families that were specifically designed to be deployed inside a network after attackers gained an initial foothold, which in many cases ended up being an RDP server.<\/p>\n<p>Ransomware specifically designed to be deployed via RDP includes strains such as CryptON, LockCrypt, Scarabey, Horsuke, SynAck, Bit Paymer, RSAUtil, Xpan, Crysis, Samas (SamSam), LowLevel, DMA Locker, Apocalypse, Smrss32, Bucbi, Aura\/BandarChor, ACCDFISA, and Globe.<\/p>\n<p>Here\u2019s just one user\u00a0recounting one event on Reddit\u00a0where hackers broke in via RDP and launched ransomware that encrypted countless of his systems.<\/p>\n<p>There are three ways in which hackers usually tend to get in. The easiest way is when sysadmins enable RDP access on a server and don\u2019t set up a password. Anyone accessing that computer\u2019s IP address on port 3389 will be prompted by a login screen where they can log in just by pressing Enter.<\/p>\n<p>The second way is derived from the first but requires on attackers either guessing login credentials (via a brute-force attack) or by using precompiled lists of common username-password combos (via dictionary attacks).<\/p>\n<p>The third method also relies on mass-scanning the internet, but instead of guessing credentials, attackers deliver exploit code for known vulnerabilities in the RDP protocol. If the port is exposed, then hackers can exploit it.<\/p>\n<p>According to Rapid7, between 2002 and late early 2017, there have been 20 Microsoft security updates specifically related to RDP, updates that fixed 24 major vulnerabilities. Patches for RDP continued even after Rapid7 stopped counting, with the latest of these fixes being deployed this March for a\u00a0flaw in CredSSP, one of the smaller protocols part of the RDP package.<\/p>\n<p>In an interview with ZDNet about the FBI\u2019s alert, Mark Dufresne, VP, Threat Research and Prevention at cyber-security Endgame, shared some of his dealings with the RDP threat.<\/p>\n<p>\u201cRDP has been baked into Windows for a very long time and has been abused by attackers since it became widely deployed,\u201d Dufresne told ZDNet.<\/p>\n<p>\u201cWe can look at sources like greynoise.io to see that attackers are constantly looking for open RDP connections,\u201d he added. \u201cAlmost a thousand unique IPs were looking for RDP services listening on the default port each day over the past week.\u201d<\/p>\n<p>Once attackers get in, it\u2019s all fair game, unless they\u2019re not careful and security products expose their presence.<\/p>\n<p>But not all RDP compromises result in ransomware infections, data theft, or malicious behavior. Some of the people behind these RDP scans don\u2019t always exploit the hacked systems \u2013at least not directly\u2013 and stockpile hacked RDP endpoints to sell online.<\/p>\n<p>Since mid-2016, just about when cyber-security firms were noting a rise in RDP servers, a group of hackers set up\u00a0xDedic, a web portal where they and other criminals could sell or buy these hacked and hoarded RDP systems.<\/p>\n<p>Initially, it was said that xDedic provided crooks access to over 70,000 hacked RDP endpoints, but one year later, despite the media attention and attempts to take down the site, xDedic\u2019s RDP server pool had gone\u00a0up to 85,000.<\/p>\n<p>But xDedic was only the beginning. Other copycat \u201cRDP shops\u201d \u2013as they became to be known as\u2013 popped up everywhere. This reporter has been tracking some of these services for the past few years on Twitter [1,\u00a02,\u00a03,\u00a04,\u00a05,\u00a06].<\/p>\n<p>The most recent of these was discovered just this summer,\u00a0in July. McAfee security researchers found it peddling access to RDP workstations located on some pretty sensitive places such as airports, government, hospitals, and nursing homes.<\/p>\n<p>But these shops wouldn\u2019t be a problem unless people stopped exposing RDP endpoints altogether. Through its alert, the FBI is now urging companies to secure these systems before it\u2019s too late and they get hacked.<\/p>\n<p>Together with the Department of Homeland Security, the two agencies have published today the following advice in regards to improving RDP security.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>FBI warns companies about hackers increasingly abusing RDP connections. Not too many of us knows the full meaning of RDP so, we are going to explain it in a brief for you to understand what this warning is all about. RDP is an acronym which means remote desktop protocol and is a proprietary protocol developed [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[],"class_list":["post-46","post","type-post","status-publish","format-standard","hentry","category-tech-news"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>FBI warns companies about hackers increasingly abusing RDP - Digitalbes Limited Premium Blog<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/cms.digitalbes.com\/?p=46\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"FBI warns companies about hackers increasingly abusing RDP - Digitalbes Limited Premium Blog\" \/>\n<meta property=\"og:description\" content=\"FBI warns companies about hackers increasingly abusing RDP connections. Not too many of us knows the full meaning of RDP so, we are going to explain it in a brief for you to understand what this warning is all about. RDP is an acronym which means remote desktop protocol and is a proprietary protocol developed [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/cms.digitalbes.com\/?p=46\" \/>\n<meta property=\"og:site_name\" content=\"Digitalbes Limited Premium Blog\" \/>\n<meta property=\"article:published_time\" content=\"2018-09-28T14:23:37+00:00\" \/>\n<meta name=\"author\" content=\"dbl\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"dbl\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/cms.digitalbes.com\\\/?p=46#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/cms.digitalbes.com\\\/?p=46\"},\"author\":{\"name\":\"dbl\",\"@id\":\"https:\\\/\\\/cms.digitalbes.com\\\/#\\\/schema\\\/person\\\/501f983dd73df2b3abf7b41c11a10904\"},\"headline\":\"FBI warns companies about hackers increasingly abusing RDP\",\"datePublished\":\"2018-09-28T14:23:37+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/cms.digitalbes.com\\\/?p=46\"},\"wordCount\":1012,\"commentCount\":0,\"articleSection\":[\"Tech News\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/cms.digitalbes.com\\\/?p=46#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/cms.digitalbes.com\\\/?p=46\",\"url\":\"https:\\\/\\\/cms.digitalbes.com\\\/?p=46\",\"name\":\"FBI warns companies about hackers increasingly abusing RDP - Digitalbes Limited Premium Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/cms.digitalbes.com\\\/#website\"},\"datePublished\":\"2018-09-28T14:23:37+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/cms.digitalbes.com\\\/#\\\/schema\\\/person\\\/501f983dd73df2b3abf7b41c11a10904\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/cms.digitalbes.com\\\/?p=46#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/cms.digitalbes.com\\\/?p=46\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/cms.digitalbes.com\\\/?p=46#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/cms.digitalbes.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"FBI warns companies about hackers increasingly abusing RDP\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/cms.digitalbes.com\\\/#website\",\"url\":\"https:\\\/\\\/cms.digitalbes.com\\\/\",\"name\":\"Digitalbes Limited Premium Blog\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/cms.digitalbes.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/cms.digitalbes.com\\\/#\\\/schema\\\/person\\\/501f983dd73df2b3abf7b41c11a10904\",\"name\":\"dbl\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/32bb84d38230af21f8f3323e55011359ebae16aa5c7b6554ae4fbbdc77b32582?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/32bb84d38230af21f8f3323e55011359ebae16aa5c7b6554ae4fbbdc77b32582?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/32bb84d38230af21f8f3323e55011359ebae16aa5c7b6554ae4fbbdc77b32582?s=96&d=mm&r=g\",\"caption\":\"dbl\"},\"sameAs\":[\"https:\\\/\\\/cms.digitalbes.com\"],\"url\":\"https:\\\/\\\/cms.digitalbes.com\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"FBI warns companies about hackers increasingly abusing RDP - Digitalbes Limited Premium Blog","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/cms.digitalbes.com\/?p=46","og_locale":"en_US","og_type":"article","og_title":"FBI warns companies about hackers increasingly abusing RDP - Digitalbes Limited Premium Blog","og_description":"FBI warns companies about hackers increasingly abusing RDP connections. Not too many of us knows the full meaning of RDP so, we are going to explain it in a brief for you to understand what this warning is all about. RDP is an acronym which means remote desktop protocol and is a proprietary protocol developed [&hellip;]","og_url":"https:\/\/cms.digitalbes.com\/?p=46","og_site_name":"Digitalbes Limited Premium Blog","article_published_time":"2018-09-28T14:23:37+00:00","author":"dbl","twitter_card":"summary_large_image","twitter_misc":{"Written by":"dbl","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/cms.digitalbes.com\/?p=46#article","isPartOf":{"@id":"https:\/\/cms.digitalbes.com\/?p=46"},"author":{"name":"dbl","@id":"https:\/\/cms.digitalbes.com\/#\/schema\/person\/501f983dd73df2b3abf7b41c11a10904"},"headline":"FBI warns companies about hackers increasingly abusing RDP","datePublished":"2018-09-28T14:23:37+00:00","mainEntityOfPage":{"@id":"https:\/\/cms.digitalbes.com\/?p=46"},"wordCount":1012,"commentCount":0,"articleSection":["Tech News"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/cms.digitalbes.com\/?p=46#respond"]}]},{"@type":"WebPage","@id":"https:\/\/cms.digitalbes.com\/?p=46","url":"https:\/\/cms.digitalbes.com\/?p=46","name":"FBI warns companies about hackers increasingly abusing RDP - Digitalbes Limited Premium Blog","isPartOf":{"@id":"https:\/\/cms.digitalbes.com\/#website"},"datePublished":"2018-09-28T14:23:37+00:00","author":{"@id":"https:\/\/cms.digitalbes.com\/#\/schema\/person\/501f983dd73df2b3abf7b41c11a10904"},"breadcrumb":{"@id":"https:\/\/cms.digitalbes.com\/?p=46#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/cms.digitalbes.com\/?p=46"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/cms.digitalbes.com\/?p=46#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/cms.digitalbes.com\/"},{"@type":"ListItem","position":2,"name":"FBI warns companies about hackers increasingly abusing RDP"}]},{"@type":"WebSite","@id":"https:\/\/cms.digitalbes.com\/#website","url":"https:\/\/cms.digitalbes.com\/","name":"Digitalbes Limited Premium Blog","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/cms.digitalbes.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/cms.digitalbes.com\/#\/schema\/person\/501f983dd73df2b3abf7b41c11a10904","name":"dbl","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/32bb84d38230af21f8f3323e55011359ebae16aa5c7b6554ae4fbbdc77b32582?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/32bb84d38230af21f8f3323e55011359ebae16aa5c7b6554ae4fbbdc77b32582?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/32bb84d38230af21f8f3323e55011359ebae16aa5c7b6554ae4fbbdc77b32582?s=96&d=mm&r=g","caption":"dbl"},"sameAs":["https:\/\/cms.digitalbes.com"],"url":"https:\/\/cms.digitalbes.com\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/cms.digitalbes.com\/index.php?rest_route=\/wp\/v2\/posts\/46","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms.digitalbes.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms.digitalbes.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms.digitalbes.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cms.digitalbes.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=46"}],"version-history":[{"count":0,"href":"https:\/\/cms.digitalbes.com\/index.php?rest_route=\/wp\/v2\/posts\/46\/revisions"}],"wp:attachment":[{"href":"https:\/\/cms.digitalbes.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=46"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms.digitalbes.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=46"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms.digitalbes.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=46"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}