Massive rise in Remote Desktop attacks since Covid-19 lockdown

February 24th 2021

Massive rise in Remote Desktop attacks since Covid-19 lockdown

Blog by Communicate Technology PLC's Lead Penetration Tester, Wynn Jones ESCA LPT CEH CHFI OSCP CCSA CVE CCA IASME certified Cyber Essentials, CE+ & Governance Assessor

Since the start of the pandemic, we have noticed a massive increase in cybercriminal attacks, with RDP (Microsoft Remote Desktop Protocol) attacks being at the top of the attack lists in 2020.

Cybercriminals and hackers are continuously implementing new attack methods to exploit remote login credentials. These are known as credential harvesting attacks.

With many companies just allowing remote desktop connections through their firewalls, with no other form of encryption or authentication validation involved, these RDP attacks are becoming more common.

The highly predicted attack rate has rocketed over the last year as employees started to work from home due to the Covid-19 restrictions. Cyber security solution provider, ESET, has recorded a 768% increase in RDP attacks between Q1 and Q4 of 2020.

In an attempt to get users working from home quickly, and with as little intervention as possible, many Managed Service Provider's (MSP’s) and IT administration departments simply opened port 3389 through the firewall to a server, or group of servers. These implementations were usually hastily configured with little regard to solid cyber security. Many of these set ups have been found to have known and exploitable vulnerabilities in them.

What this means is that companies then have the issue that end users can use their own personal PC’s or laptops to connect to the corporate network. Many of these devices may already have malware ticking away in the background, without the end users being aware of it, especially with the possibility that there could be a keystroke logger installed. These loggers detect anything typed on the keyboard and at certain points of the day and send that information to a C&C (Command & Control) server out on the internet.

When it comes to Cyber Security you should get a qualified and experienced Cyber Security expert to review your set up.

Unfortunately, most IT departments and service providers are rushed into implementing solutions, usually by senior management or board level members, which are not fit for modern day Cyber Security needs. Most IT administrators and managers are not trained in advanced hacking techniques and do not realise they are opening their doors to the bad guys. Hastily implemented solutions which are made for “ease of implementation and end user access” are a cybercriminal’s dream.

Don’t forget it maybe that your network is part of a connected supply chain. Therefore, you may be opening up your client’s networks as well.

Don’t be an easy mark for the cybercriminals or unscrupulous competitors. Get a check by a company who knows what to look for and can give sound advice on how to prevent cyber-attacks. Please get in touch if you’d like to discuss your options enquiries@communicateplc.com.

        

wave

Help to Grow Management Programme 2026

Teesside University have been awarded funding again for 2026/27 to deliver the Help to Grow Management Course. They have been running it now since 2022, the feedback from participants is...

READ MORE

Accountancy firm welcomes new senior expert

A North East chartered accountancy practice has welcomed a new senior manager, strengthening its support for the firm’s growing portfolio of clients. Stockton-based Baines Jewitt has appointed...

READ MORE
wave
line

If you would like to become a member simply click the join button below. If you haven’t already attended one of our events, and would like to experience the benefits of club membership for yourself firsthand before you join, you can come along to one of our events as a guest. If you would like to do this please visit our events page, select the event you would like to attend, and complete your registration details in the box at the bottom of the page. Please note that guest places at each event are limited and available on a first served basis.

 

wave
line