HomeSecurityRDP and VPN Vulnerabilities: The Favorite Exploits of Ransomware Groups

RDP and VPN vulnerabilities: The favorite exploits of ransomware groups

ransomware

Ransomware attacks targeting corporate networkswere more prevalent than ever in the first half of 2020. Typically, ransomware gangs attack using their own tools, however, most ransomware incidents in the first half of 2020 can be attributed to the use of specific exploits. The three most popular exploits for ransomware attacks include unsecured RDP endpoints, email phishing, and corporate VPN exploitation.

RDP VPN
RDP: Number 1 on the list of exploits

At the top of this list is the RDP protocol. Reports from Coveware, Emsisoft , and Recorded Future clearly place RDP as the most popular exploit and the source of most ransomware attacks in 2020.

“Today, RDP is considered the largest attack for ransomware,” Emsisoft said last month.

Statistics from Coveware, a company that provides ransomware countermeasures and services , also support this. The company says that RDP is the most popular entry point for ransomware attacks.

Furthermore, according to Recorded Future: “Remote Desktop Protocol is currently the most common attack vector used by threat actors to gain access to computers Windows and install ransomware and other malware.”

Some may think that RDP is often used by ransomware gangs due to the current situation where most people are working from home. However, this is wrong and inaccurate. Hackers have been exploiting RDP since last year when they stopped targeting home users and started focusing on corporate networks.

RDP is the leading technology for connecting to remote systems, and there are millions of computers with RDP ports exposed on the internet, making RDP the most popular exploit among cybercriminals (not just ransomware gangs).

Many hackers specialize in scanning the Internet for RDP endpoints and then performing brute-force attacks against these systems in an attempt to guess their credentials.

Systems that use weak username and password combinations are easily compromised and then put up for sale in so-called “RDP shops,” where they are purchased by various criminal groups.

Today, ransomware gangs are the biggest customers of RDP stores, and some store managers have closed their stores to work exclusively with ransomware gangs or have become customers of Ransomware-as-a-Service (RaaS) portals to earn revenue from the collection of hacked RDP systems at their disposal.

exploits
VPN: The new RDP

However, in 2020 it was observed that ransomware gangs began to heavily exploit VPN to gain access to corporate networks.

Since the summer of 2019, many serious vulnerabilities in devices VPN

With the publication of PoC exploits, many hackers began exploiting the bugs to gain access to corporate networks.

Some ransomware gangs started using this exploit last year, but the number of attacks based on it increased significantly in 2020.

During 2020, VPNs began to be used by ransomware groups, with Citrix network gateways and Pulse Secure VPN servers being their favorite targets, according to a report published last week by SenseCy.

According to SenseCy, gangs such as REvil (Sodinokibi), Ragnarok, DoppelPaymer, Maze, CLOP, and Nefilim have used systems Citrix to gain access to corporate networks. Also, groups such as REvil and Black Kingdom have used Pulse Secure VPN, vulnerable to the CVE-2019-11510 flaw.

Security experts constantly emphasize the need for regular updates of systems, devices, applications , etc.

Regularly updating VPNs and using strong RDP credentials are essential to protecting companies.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS