Coordinated Scans Target Microsoft RDP Authentication Portals
HighWhat happened
A significant surge in coordinated scanning activity has been detected, with nearly 1,971 unique IP addresses probing Microsoft Remote Desktop Web Access and RDP Web Client authentication portals simultaneously. This suggests a large-scale reconnaissance effort aimed at identifying potential vulnerabilities.
Who is affected
Organizations utilizing Microsoft Remote Desktop Protocol (RDP) services, particularly those with exposed authentication portals, are at risk of being targeted by these scans.
Why it matters
The coordinated nature and scale of these scans indicate a potential precursor to credential-based attacks, such as brute-force or password-spraying attempts. Exploitation of timing flaws in RDP authentication could allow attackers to verify valid usernames, facilitating unauthorized access.
How it could have been prevented
- Implementing multi-factor authentication (MFA) for RDP access to add an additional layer of security. - Regularly monitoring and analyzing network traffic to detect and respond to unusual scanning activities promptly.
Relevant professional terms
- Brute-force attack
- A method where attackers systematically try all possible combinations of passwords or encryption keys until the correct one is found.
- Password-spraying attack
- An attack technique where a single password is tried against many accounts to avoid detection and account lockouts.
Recommended reading: RDP brute-force attacks are skyrocketing due to remote working
