Just 2020 things: Miscreants hit remote desktops 700% harder as world's IT teams try to support locked-down staff
- Reference: 1612880769
- News link: https://www.theregister.co.uk/2021/02/09/eset_threat_report_2020/
- Source link:
During calendar 2020, ESET recorded what it said was a 768 per cent increase in attack attempts on RDP, a key Windows feature for remote working, during the course of the year.
[1]
Roman Kováč, ESET's chief research officer, said in a [2]statement : "RDP security is not to be underestimated especially due to ransomware, which is commonly deployed through RDP exploits, and, with its increasingly aggressive tactics, poses a great risk to both private and public sectors."
Lest anyone be alarmed by this, he added: "As the security of remote work gradually improves, the boom in attacks exploiting RDP is expected to slow down – we already saw some signs of this in Q4."
[3]
Figures published by ESET showed that in January 2020 the number of brute-force RDP connection attempts tracked by the company were running at less than 10 million. By December that number had peaked at more than 225 million in total – and in Q4 around 150,000 of those were targeted against unique devices.
Scottish enviro bods shrug off ransomware gang's extortion attempt as 4,000 files dumped online, saying it's nothing big [4]READ MORE
There is an obvious reason why connection attempts targeted at RDP took place: COVID-19. As well as the uptick in malicious RDP connection attempts, ESET also noted (not uniquely) an increase in coronavirus-themed phishing lures over the course of the year, which it said was "especially related to the end-of-year vaccine rollouts."
Those attacks have taken a back seat to more eye-catching forms (yes, we mean ransomware) over the past 12 months, though research by infosec outfit Check Point in 2019 [5]showed that common RDP tools for Windows and Linux alike were festooned with vulns. Perhaps somebody other than the vendor paid attention to those findings.
The full 2020 threat report, available from ESET's website, also detailed how North Korea's APT38 (known by ESET as Lazarus) hijacked legitimate banking security software called WIZVERA VeraPort as part of a supply-chain attack, and other elements of its research.
[6]
A couple of years ago a Slovakian Communist politician [7]claimed Slovakia-based ESET was staffed with "outrageous fascists" who bribed local politicians and media outlets for positive coverage and favourable policies. Unsurprisingly, he was forced to delete those baseless claims after the company [8]sued him over them. ®
Get our [9]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YCK-pbCdOPo4D6wzEa0r1AAAAJc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://www.eset.com/us/about/newsroom/press-releases/eset-issues-its-q4-2020-threat-report-recording-a-massive-increase-in-rdp-attack-attempts-since-q1-1/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YCK-pbCdOPo4D6wzEa0r1AAAAJc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://www.theregister.com/2021/01/22/sepa_ransomware_failure/
[5] https://www.theregister.com/2019/02/05/rdp_check_point_vulnerabilities/
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YCK-pbCdOPo4D6wzEa0r1AAAAJc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2019/07/12/eset_slovakian_mp_lawsuit/
[8] https://spectator.sme.sk/c/22324139/court-ordered-smer-mp-blaha-to-erase-false-posts-about-eset.html
[9] https://whitepapers.theregister.com/
RDP over the internet
Personally, don't see why any IT staff worth their salt would think RDP direct over the internet would be a good thing.
I would assume that a number of these would be management who would say "just get it done but there's no budget for it"
It would be scary to think there are people out there who profess It knowledge that think it would be a good idea.
I can understand if it's very small companies who don't know the repurcussions of allowing something like this.
Re: RDP over the internet
> I would assume that a number of these would be management who would say "just get it done but there's no budget for it"
There's also "get it done right NOW because everyone's working at home due to covid" and not only is there no budget, but there's no time to do it right.
That RDP would be a target nowadays is hardly a surprise. I'd be interested to hear from the sysadmins out there to hear what they have to say.
Is it as bad as ESET make out? And are the problems primarily down to end-users not having their home machines not properly updated, to the protocol itself and was this a disaster waiting to happen?