Cybercriminals are becoming more aggressive in their attempts to break into RDP services with attempts to exploit weak passwords used on corporate networks, researchers warn.

See also: Microsoft: New FoggyWeb malware is a backdoor for hackers
Computer networks are being bombarded with billions of password-guessing attacks as hackers try to exploit the growth of Remote Desktop Protocol (RDP) and other cloud services in corporate environments.
Cybersecurity researchers at ESET detected 55 billion new brute-force attack attempts between May and August 2021 alone—more than double the 27 billion attacks detected between January and April.
Successfully guessing passwords can provide cybercriminals with an easy route into networks and a route they can use to launch further attacks, including delivering ransomware or other malware. Once on a network, they will attempt to use this access to gain additional privileges and manipulate the network, performing actions such as disabling security services so they can more easily carry out their activities.
See also: Why do hackers compromise Windows IIS servers?
One of the most popular targets for brute-force password-guessing attacks is RDP services. The rise of remote working has led to an increase in people needing to use remote desktop services. Many of these are public services, providing cybercriminals with an opportunity to infiltrate networks – and it’s an opportunity they’re eager to exploit.
The sheer number of attacks means that most are automated, but if accounts are secured with common passwords then they can become easy targets for attackers. Once a password has been successfully compromised, it is likely that an attacker will take a more hands-on approach to reach their ultimate goal.
In addition to targeting RDP services, cybercriminals are also targeting public SQL and SMB services. These services are often protected with default passwords that attackers can exploit.
One of the reasons brute-force attacks are successful is because so many accounts are protected with simple one-word passwords. Requiring more complex passwords could go a long way in preventing accounts from being compromised in brute-force attacks. The National Cybersecurity Center recommends that users use three words as a password.
See also: FBI and CISA: Hackers exploit critical Zoho bug
Organizations can also provide an additional layer of protection against brute-force password-guessing attacks by deploying multi-factor authentication (MFA). Using MFA means that, even if attackers know the correct password, there is an additional barrier to prevent automatic network access.
Information source: zdnet.com
