Follow Naijacrux on twitter .follow us on Twitter www.twitter.com/naijacruxonline, or @naijacruxonline or search for naijacruxonline on twitter!!Like us on facebook .Like us at www.facebook.com/Naijacruxforum.Click Here To Last longer In Bed[Stay amused>>>Don’t be a one minute Foul]>>> Love need Tips-See how Here


Author Topic: New Ransomware now Infects Computers via Windows Remote Desktop Services  (Read 2183 times)

0 Members and 1 Guest are viewing this topic.

Offline legendguru

  • Global Moderator
  • Hero Member
  • *****
  • Posts: 2644
  • Karma: +1/-0
Advertisement

A new strain of ransomware is using the Windows built-in Remote Desktop Services or Terminal Services to infect computers, encrypt files, and then demand a ransom of 4 Bitcoin (~$1,000).

The ransomware was first seen for users in Bulgaria and Greece, a few of whom asked for help online, on the Bleeping Computer tech forums. Malware researcher Nathan Scott took a closer look at this new ransomware family and found some interesting things.

Attackers are brute-forcing passwords on PCs running Remote Desktop Services

According to his findings, the attackers are manually installing the ransomware on all infected devices by brute-forcing user account passwords on machines that have left Remote Desktop or Terminal Services connections open.

Once they manage to get a foothold on infected systems, the attackers run the ransomware executable, which first maps all local and network drives.