Ransomware spreads through weak remote desktop credentials

Ransomware spreads through weak remote desktop credentials

digitalkey1-10060082

 

A new ransomware program in Brazil uses RDP brute-force attacks to infect hospitals

 

Stolen or weak remote desktop credentials are routinely used to infect point-of-sale systems with malware, but recently they’ve also become a common distribution method for file-encrypting ransomware.

In March, researchers discovered a ransomware program dubbed Surprise that was being installed through stolen credentials for TeamViewer, a popular remote administration tool. But the trend had started long before that, with some ransomware variants being distributed through brute-force password guessing attacks against Remote Desktop Protocol (RDP) servers since 2015.

While this method of infection was initially used by relatively obscure ransomware programs, recently it has been adopted by an increasing number of cybercriminals, including those behind widespread ransomware programs such as Crysis.

Security researchers from antivirus firm Kaspersky Lab have discovered a new ransomware program that affected hospitals and other organizations in Brazil. The researchers have named the threat Trojan-Ransom.Win32.Xpan and say it’s the creation of a gang called TeamXRat, which previously specialized in remote access trojans (RATs).

According to Kaspersky Lab, the TeamXRat attackers peform brute-force attacks against internet-connected RDP servers and then manually install the Xpan ransomware on the hacked servers.

“Connecting remote desktop servers directly to the Internet is not recommended and brute forcing them is nothing new; but without the proper controls in place to prevent or at least detect and respond to compromised machines, brute force RDP attacks are still relevant and something that cybercriminals enjoy,” the Kaspersky researchers said in a blog post. “Once the server is compromised, the attacker manually disables the Antivirus product installed on the server and proceeds with the infection itself.”

Brazil has more compromised RDP servers being sold on the underground market than any other country. It is followed by Russia, Spain, the U.K. and the U.S.

Fortunately in the case of Xpan, the ransomware authors made an error in their encryption implementation that allowed Kaspersky Lab to develop a method of recovering affected files without paying the ransom. There’s no downloadable decryption tool, but Xpan victims are advised to contact the security company’s support department and ask for assistance.

October 3, 2016 / by / in , , , , , , , , ,

Leave a Reply

Show Buttons
Hide Buttons

IMPORTANT MESSAGE: Scooblrinc.com is a website owned and operated by Scooblr, Inc. By accessing this website and any pages thereof, you agree to be bound by the Terms of Use and Privacy Policy, as amended from time to time. Scooblr, Inc. does not verify or assure that information provided by any company offering services is accurate or complete or that the valuation is appropriate. Neither Scooblr nor any of its directors, officers, employees, representatives, affiliates or agents shall have any liability whatsoever arising, for any error or incompleteness of fact or opinion in, or lack of care in the preparation or publication, of the materials posted on this website. Scooblr does not give advice, provide analysis or recommendations regarding any offering, service posted on the website. The information on this website does not constitute an offer of, or the solicitation of an offer to buy or subscribe for, any services to any person in any jurisdiction to whom or in which such offer or solicitation is unlawful.