HomeSecurity7,000 organizations' "Network access" sold on hacking forums

“Network access” of 7,000 organizations is being sold on hacking forums

Hackers have breached 7,500 organizations and are selling “network access” on several Russian hacking forums.

An investigation by CyberNews.com reveals that the compromised networks are located in the US, Canada and Australia and include educational and entertainment organizations.

Remote Desktop Protocol (RDP) access is being sold via auction on hacking forums, with the starting bid for the entire package starting at 25 BTC (about $330,000) and the “Buy now” option selling for 75 BTC (about $1,000,000).

hacking forums

The access package would be a great buy for a new and aspiring ransomware, as attacking 7,500 organizations would help the group become famous in a short period of time.

RDP has a number of security holes, including the BlueKeep vulnerability (CVE-2019-0708), which make it extremely easy for threat actors to exploit. IoT search engine Shodan.io reveals that there are millions of devices worldwide with open RDP ports.

"Network access" of 7,000 organizations is being sold on hacking forums

As you can see above, millions of devices are still open to the public . This doesn't mean that all of these machines are necessarily vulnerable to cyberattacks: some may be false positives, while others may be patched or otherwise protected from common RDP-related vulnerabilities

However, considering how actively this attack vector is exploited by cybercriminals in general and ransomware gangs in particular, one can safely assume that a non-trivial percentage of open devices are vulnerable.

“Between the sharp increase in attacks targeting RDPs, the phenomenal growth of the ransomware industry, and the overall increase in cybercrime in recent years, organizations now have no excuse to compromise their networks due to ancient vulnerabilities, which are a direct result of not updating their systems,” says Edvardas Mikalauskas of CyberNews.

Organizations should patch the vulnerability and make sure they don't leave machines with RDP ports open where the vulnerability hasn't been patched.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS