CERT mailing list archives

IC3 Issues Alert on RDP Exploitation


From: "US-CERT" <US-CERT () ncas us-cert gov>
Date: Fri, 28 Sep 2018 10:25:23 -0500

U.S. Department of Homeland Security US-CERT

National Cyber Awareness System:



IC3 Issues Alert on RDP Exploitation [ 
https://www.us-cert.gov/ncas/current-activity/2018/09/28/IC3-Issues-Alert-RDP-Exploitation ] 09/28/2018 09:54 AM EDT 
Original release date: September 28, 2018

The Internet Crime Complaint Center (IC3), in collaboration with DHS and the Federal Bureau of Investigation, has 
released an alert on cyber threat actors maliciously using legitimate remote administration tools, such as Remote 
Desktop Protocol (RDP). Threat actors identify and exploit vulnerable RDP sessions to facilitate credential theft and 
ransomware infection.

NCCIC encourages users and administrators to review the IC3 Alert [ https://www.ic3.gov/media/2018/180927.aspx ] and 
the NCCIC Tips on Securing Network Infrastructure Devices [ https://www.us-cert.gov/ncas/tips/ST18-001 ] and Choosing 
and Protecting Passwords [ https://www.us-cert.gov/ncas/tips/ST04-002 ]. If you believe you are a victim of cybercrime, 
file a complaint with IC3 at www.ic3.gov [ https://www.ic3.gov/default.aspx ].

________________________________________________________________________

This product is provided subject to this Notification [ http://www.us-cert.gov/privacy/notification ] and this Privacy 
& Use [ http://www.us-cert.gov/privacy/ ] policy.

body { font-size: 1em; font-family: Arial, Verdana, sans-serif; font-weight: normal; font-style: normal; color: 
#333333; } ________________________________________________________________________

A copy of this publication is available at www.us-cert.gov [ https://www.us-cert.gov ]. If you need help or have 
questions, please send an email to info () us-cert gov. Do not reply to this message since this email was sent from a 
notification-only address that is not monitored. To ensure you receive future US-CERT products, please add US-CERT () 
ncas us-cert gov to your address book. 

OTHER RESOURCES: Contact Us [ http://www.us-cert.gov/contact-us/ ] | Security Publications [ 
http://www.us-cert.gov/security-publications ] | Alerts and Tips [ http://www.us-cert.gov/ncas ] | Related Resources [ 
http://www.us-cert.gov/related-resources ]  

STAY CONNECTED: Sign up for email updates [ http://public.govdelivery.com/accounts/USDHSUSCERT/subscriber/new ] 


Current thread: