Ransomware cyber attacks are moving on from their indiscriminate wide-scale deployment in the last two years to a more targeted approach in 2018. The NCSC Advisory Report: Ongoing threat to organisations from ransomware, confirms that this type of cyber attack was previously profitable because of its economy of scale. In 2017, cyber criminals were successful by the random targeting of high volumes of organisations. Even with modest ransom demands of a few hundreds of pounds, it proved to be very lucrative. Ransomware attacks in 2018 have been more targeted with the victims increasingly being larger companies or high net-worth individuals with a public profile.
Ransom based on perceived value
Ransomware cyber attacks are feared by organisations worldwide. In restricting access to critical files and systems, they can disrupt business in a matter of minutes. Rather than reporting the attack to law enforcement agencies, many still pay the ransom quickly to resolve the problem and avoid any loss of reputation and regulatory fines.
One of the ‘unwritten rules’ of cyber crime is that if an attack vector works on a larger scale, it will then be combined with social engineering tactics to focus on more specific targets that yield a higher return. The NCSC reports they have seen a growing trend in more targeted ransomware attacks in the last nine months. Criminal actors analyse victim networks to understand their ‘value’ and set a ransom demand based on that perceived value.
Increase in RDP attacks
The NCSC also highlights the increasing number of ransomware attacks using remote administration tools, such as Remote Desktop Protocol (RDP). Included in every version of Microsoft Windows since 2001, RDP was previously known as Terminal Services Client and later as Remote Desktop Connection. While rarely used by system administrators these days, it has always been a favourite of hackers who use it to take control of a remote computer or virtual machine over a network connection. Cyber actors have developed new methods of identifying and exploiting RDP vulnerable networks by stealing usernames and passwords of authorised staff using brute-force techniques. Less talented cyber criminals can buy this valuable information which is available for a low price on the Dark Web.
Rapid 7 detect RDP skyrockets in May
Security specialist, Rapid 7, has also confirmed a record number of RDP attacks in 2018. Their Quarterly Threat Report 2018 Q2 shows that daily RDP incidents ‘skyrocketed’ in May, with attackers in most cases attempting to copy backups. They commented, “Monitoring for brute-force activity, suspicious multi-country authentication and multi-organisation authentication helps to identify RDP attacks. Implementing multi-factor authentication and monitoring for leaked credentials can help organisations actively protect themselves from these threats.”
FBI Public Service Announcement
The need to protect against RDP attack is further supported by a recent US Public Service Announcement issued by the FBI and Department of Homeland Security (DHS). The announcement identifies vulnerabilities that include weak passwords that allow attackers to initiate RDP connections, outdated versions of RDP with weak encryption, unrestricted access to the default RDP port (3389), and allowing unlimited login attempts to a user account.
Special mention goes to ransomware threats such as CrySiS, which targets businesses through open RDP ports and CryptON, which uses brute-force password attacks to gain access to RDP sessions. In just two and a half years, SamSam ransomware campaigns using RDP attacks are believed to have netted nearly $6million for cyber criminals in the USA.
Advice from the FBI and DHS on how to mitigate against RDP attacks includes:
- Enable strong passwords and account lockout policies
- Apply two-factor authentication (2FA)
- Apply system and software updates regularly
- Maintain a good backup strategy
- Enable logging and ensure log mechanisms capture RDP logins
- Minimise network exposure by disabling RDP ports not being used
Many of these suggestions are in UK government cyber security best practice guides such as the Cyber Essentials scheme and the NCSC 10 Steps to Cyber Security. We should all remember that the only way the UK National Health Service recovered from the devastating WannaCry ransomware attack of 2017 was by restoring its backups.
—————–
Ransomware protection is a key feature of our CYBERSHIELD MDR-COMPLETE service package. Functioning as your company’s own 24/7 cyber security operations centre, we monitor critical network infrastructure and endpoint devices, proactively hunting for threats and providing actionable remediation when required. RDP attacks are detected before they happen by continually checking for brute-force activity and any suspicious authentication from more than one location or country.


