{"id":55129,"date":"2023-04-05T11:42:58","date_gmt":"2023-04-05T03:42:58","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=55129"},"modified":"2023-04-05T11:43:00","modified_gmt":"2023-04-05T03:43:00","slug":"remote-desktop-attacks-drop-in-sea-post-pandemic","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2023\/04\/05\/remote-desktop-attacks-drop-in-sea-post-pandemic\/","title":{"rendered":"Remote desktop attacks drop in SEA post-pandemic"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>Kaspersky revealed the drop in Bruteforce attacks against remote workers in Southeast Asia (SEA), a positive news that should not be taken as a sign to be complacent.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Remote Desktop Protocol (RDP) is Microsoft\u2019s proprietary protocol, providing a user with a graphical interface to connect to another computer through a network. RDP is widely used by both system administrators and less-technical users to control servers and other PCs remotely.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/threats.kaspersky.com\/en\/threat\/Bruteforce.Generic.RDP\/\">Bruteforce.Generic.RDP<\/a> attack attempts to find a valid RDP login\/password pair by systematically checking all possible passwords until the correct one is found. A successful attack allows an attacker to gain remote access to the targeted host computer.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Global cybersecurity company\u2019s telemetry showed Kaspersky\u2019s B2B solutions have blocked a total of 75,855,129 Bruteforce.Generic.RDP incidents targeting companies in SEA last year.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">2022\u2019s total number is a 49% dip from 2021\u2019s 149,003,835 Bruteforce attacks. The decline in quantity has been observed across all the six countries in SEA.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In terms of share of Bruteforce attacks last year, companies in Vietnam, Indonesia, and Thailand were targeted the most.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cFrom almost 150 million Bruteforce attacks against companies here in 2021, last year witnessed just half of them. It\u2019s a good sign at first glance. In part, this was influenced by shifting to either a pure face-to-face or a hybrid remote environment, which means there are fewer remote workers in the region as compared to the peak of the pandemic in 2022 and 2021,\u201d explains Yeo Siang Tiong, General Manager for Southeast Asia at Kaspersky.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cIt is, however, too early for businesses to proclaim total safety from Bruteforce attacks. Looking at the wider threat landscape, our experts see more modern ransomware groups exploiting RDP to gain initial access to the enterprise they are targeting. It\u2019s a red flag that security teams should pay close attention to,\u201d Yeo adds.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A recent Kaspersky <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/securelist.com\/modern-ransomware-groups-ttps\/106824\/\">report<\/a> unmasked the most popular techniques for gaining initial access among ransomware groups. Exploiting external remote services came up as the most common for the ransomware groups analyzed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In fact, all of the eight ransomware groups covered in the report which are mostly operating as a RaaS (Ransomware as a Service) \u2013 Conti, PysaClop (TA505), Hive, Ragnar Locker, Lockbit, BlackByte, and BlackCat \u2013 use valid accounts, stolen credentials or Bruteforcing to get into a victim\u2019s networks.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The report also notes all of the ransomware groups used open RDP to gain initial access to the system as this is the easiest vector for initial access.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A best practice for protecting against RDP-related attacks is to &#8220;hide&#8221; it behind a VPN and properly configure it. It is also very important to use strong passwords.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To reduce the risk and impact of a ransomware attack caused by RDP Bruteforce, Kaspersky experts also suggest deploying a comprehensive defensive concept that equips, informs and guides your team in their fight against the most sophisticated and targeted cyberattacks like the <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/go.kaspersky.com\/expert\">Kaspersky Extended Detection and Response (XDR)<\/a> platform.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Find out more about this new platform at <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/go.kaspersky.com\/expert\">go.kaspersky.com\/expert&nbsp; <\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Kaspersky in Southeast Asia also has launched a Buy 1 Free 1 promo. Businesses can now enjoy two years of enterprise-grade endpoint protection for the price of 1 with Kaspersky Endpoint Security for Business or Cloud or Kaspersky Endpoint Detection and Response Optimum, with 24&#215;7 phone support. Interested customers can reach out to <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"mailto:sea.sales@kaspersky.com\">sea.sales@kaspersky.com<\/a>.&nbsp;&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A best practice for protecting against RDP-related attacks is to &#8220;hide&#8221; it behind a VPN and properly configure it. It is also very important to use strong passwords.\u00a0<\/p>\n","protected":false},"author":6,"featured_media":55130,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19],"tags":[286,101,54,2103],"class_list":["post-55129","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","tag-it-security","tag-kaspersky","tag-security","tag-security-breach"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/55129","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=55129"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/55129\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/55130"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=55129"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=55129"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=55129"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}