RDP used by Iranian hacker to hit businesses and organizations with Dharma ransomware
Researchers have discovered a new ransomware campaign instigated by a Persian-speaking hacker group supposedly based in Iran.
Hackers are targeting businesses in Russian, Japan, India, and China to deploy Dharma ransomware by leveraging the Remote Desktop Protocol (RDP). Dharma ransomware made headlines in January 2017 after hacking a popular horse racing website in India.
In February 2017 after two Romanian hackers were arrested for hacking DC security cameras before the official inauguration ceremony of President Donald Trump. Both hackers were accused of distributing Dharma and Cerber ransomware.
A Russian company has its network breached because of exposed RDP connections which were exploited by Dharma ransomware actors. The same attack artifacts were later identified in the networks of many other companies in China, India, and Japan.
Hackers identify their targets by scanning the internet for IP address ranges for exposed or weak remote desktop connections. At this stage, they use the open-source port scanner Masscan. The researchers have termed these attacks as unprofessional and financially motivated.
NPAV requests users and organizations to immediately change those default ports that they use for RDP connections and implement account lockout measures. Install NPAV on your devices to avail best in class protection from all kinds of ransomware attacks.
Use NPAV and join us on a mission to secure the cyber world.
- Other (42)
- Ransomware (123)
- Events and News (26)
- Features (44)
- Security (422)
- Tips (79)
- Google (22)
- Achievements (8)
- Products (33)
- Activation (7)
- Dealers (1)
- Bank Phishing (42)
- Malware Alerts (187)
- Cyber Attack (219)
- Data Backup (11)
- Data Breach (75)
- Phishing (138)
- Securty Tips (1)
- Browser Hijack (16)
- Adware (15)
- Email And Password (67)
- Android Security (55)
- Knoweldgebase (38)
- Botnet (15)
- Updates (3)
- Alert (70)
- Hacking (57)
- Social Media (7)
- vulnerability (53)
- Hacker (31)
- Spyware (8)
- Windows (6)
- Microsoft (21)
- Uber (1)
- YouTube (1)
- Trojan (2)
- Website hacks (3)
- Paytm (1)
- Credit card scam (1)
- Telegram (3)
- RAT (5)
- Bug (3)
- Twitter (2)
- Facebook (7)
- Banking Trojan (5)
- Mozilla (2)
- COVID-19 (5)
- Instagram (2)
- NPAV Announcement (5)
- IoT Security (1)
- Deals and Offers (1)
- Cloud Security (8)
- Offers (5)
- Gaming (1)
- FireFox (2)
- LinkedIn (2)
- WhatsApp (4)
- Amazon (1)
- DMart (1)
- Payment Risk (4)
- Occasion (2)
- firewall (1)
- Cloud malware (2)
- Cloud storage (2)
- Financial fraud (4)
- Impersonation phishing (1)
- DDoS (4)
- Smishing (2)
- Whale (0)
- Whale phishing (3)
- WINRAR (2)
- ZIP (2)