
According to telemetry data, the number of daily brute-force attacks targeting Windows remote desktop service (RDP) nearly doubled during the lockdown.
During this time, due to COVID-19, many employees have been forced to switch to remote work. This means they are not relying on the company's monitored infrastructure. However, they continue to have access to sensitive information on the company network.
Thousands of brute-force attacks on a daily basis
Remote work has forced many employees to use their personal device to connect to the work environment, via remote desktop services . The Windows Remote Desktop protocol is the most widespread.
Many users, emphasizing convenience, create easy-to-use passwords without implementing additional layers of security, such as two-factor authentication.
Cybercriminals have not missed this opportunity and have increased the number of brute-force attacks targeting RDP services. Malicious hackers want to gain access to a company's network, gain administrator privileges, and deploy malware.
Telemetry data recorded by cybersecurity firm ESET, since December 1, 2019, shows a sharp increase in the daily number of brute-force attacks against RDP services.
From December 2019 to February 2020, attacks were between 40,000 and 70,000. The upward trend began in February, when the number reached 80,000.
In April and May, attacks reached 100,000. During this period, a total lockdown.

According to ESET, most of the brute-force attacks between January and May 2020 came from IP addresses in the US, China, Russia, Germany and France. Most of the targeted IP addresses were in Russia, Germany, Brazil and Hungary.
The company says ransomware of is the primary risk following an RDP breach. However, cryptocurrency mining and the installation backdoors are also potential threats.
ESET provides the following scenarios that could follow an RDP breach:
- Clearing log files to remove evidence of previous malicious activity
- Downloading and running tools and malware
- Disabling backups or even deleting them
- Stealing data from the servers
ESET says that one way to avoid brute-force attacks is to disable the RDP connection, which can be accessed from the Internet.
Of course, this should be combined with other security measures, such as implementing multi-factor authentication and using unique and strong passwords for all accounts accessible via RDP. Finally, increased protection is also provided by installing a VPN.
