Login Register






New Brute-Force Botnet Targeting Over 1.5 Million RDP Servers Worldwide filter_list
Author
Message
New Brute-Force Botnet Targeting Over 1.5 Million RDP Servers Worldwide #1
New Brute-Force Botnet Targeting Over 1.5 Million RDP Servers Worldwide


Security researchers have discovered an ongoing sophisticated botnet campaign that is currently brute-forcing more than 1.5 million publicly accessible Windows RDP servers on the Internet.
Dubbed GoldBrute, the botnet scheme has been designed in a way to escalate gradually by adding every new cracked system to its network, forcing them to further find new available RDP servers and then brute force them.
To fly under the radar of security tools and malware analysts, attackers behind this campaign command each infected machine to target millions of servers with a unique set of username and password combination so that a targeted server receives brute force attempts from different IP addresses.


[Image: bkwxsZs.png]

Certainly a very interesting article that I came across. It raises all kind of questions, currently there's an unpacthed vulnerability within Windows that allows client-side attackers to bypass the lock screen on remote desktop (RD) sessions.
This could potentially cause havoc around the world, which could be much worse than the WannaCry and NotPetya wormable attacks were in 2017.

Source: https://thehackernews.com/2019/06/window...force.html


Ransomware is more about manipulating vulnerabilities in human psychology than the adversary’s technological sophistication.

Reply

RE: New Brute-Force Botnet Targeting Over 1.5 Million RDP Servers Worldwide #2
Well this is nothing new so

Reply

RE: New Brute-Force Botnet Targeting Over 1.5 Million RDP Servers Worldwide #3
Wow, that's a pretty damn ingenious idea. But it's inevitable when you have a group of bored criminals.

Reply