RDP를 이용하는 공격 기법 및 사례 분석

2022-10-12 • Ahnlab • Analysis of attack techniques and cases using RDP •

https://asec.ahnlab.com/ko/39804/

Thumbnail for RDP를 이용하는 공격 기법 및 사례 분석

AhnLab explains how attackers use Windows Remote Desktop Protocol for initial access, lateral movement, and persistence after obtaining credentials or enabling remote desktop services. The report cites ransomware and APT cases where attackers used RDP directly, opened firewall rules, enabled the service with scripts, or tunneled RDP through tools such as Plink after compromising servers. It also describes RDP Wrapper abuse, including Kimsuky deployments on AppleSeed-infected systems, and cases where attackers create new local accounts for persistent access. The report frames RDP monitoring, credential hygiene, and remote-access hardening as core controls against enterprise compromise.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 68921f24e13ecc15b5692256b801172… 2022-10-12 2022-10-12
HASH 303243e4a8bf71cbb208d608277ab25… 2022-10-12 2022-10-12
HASH db74fa7e8e62c8583437e68d6e0018b… 2022-10-12 2022-10-12
IPv4 80.66.76.22 2022-10-12 2022-10-12

Related Reports

« Back