Remote Desktop Protocol – Tech | Business | Economy https://techeconomy.ng Tech | Business | Economy Wed, 27 Aug 2025 07:59:58 +0000 en-GB hourly 1 https://wordpress.org/?v=7.0 https://techeconomy.ng/wp-content/uploads/2025/06/cropped-256Px-32x32.png Remote Desktop Protocol – Tech | Business | Economy https://techeconomy.ng 32 32 Africa: Remote Desktop Protocol attacks Down 53% in Q2 2022 – Kaspersky reports https://techeconomy.ng/africa-remote-desktop-protocol-attacks-down-53-in-q2-2022-kaspersky-reports/ https://techeconomy.ng/africa-remote-desktop-protocol-attacks-down-53-in-q2-2022-kaspersky-reports/#respond Wed, 28 Sep 2022 11:33:04 +0000 https://techeconomy.ng/?p=84889 According to Kaspersky telemetry, the number of brute force attacks against Remote Desktop Protocol (RDP) across Africa has significantly decreased in Q2 2022 by 53% compared to the previous quarter.

This downward trajectory could be a result of several reasons.

https://techeconomy.ng/2022/09/why-understanding-the-threat-of-rdp-attacks-in-a-remote-working-world-is-critical/

This could be due to the Remote Desktop Protocol vulnerabilities exposed in the first quarter of the year, due to the workforce switching from remote to hybrid work, or due to organisations adopting secure RDP configurations for their remote employees, making it then a less attractive target.

RDP is a popular protocol used by employees to connect to corporate resources, servers and networks remotely.

Attacks against Remote Desktop Protocol are considered some of the most common tactics used by cybercriminals to explore security vulnerabilities and target computers within an organisation’s network. 

By exploiting insecure or incorrectly configured RDP settings, cybercriminals can log into the system without the victim’s permissions and install ransomware or steal sensitive data.

In the first quarter of 2022, the detections in Africa were at 4,345,883 as compared to the detections in the second quarter which stood at 2,056,076. Despite the decrease, RDP attacks should still be a concern for organisations as they continue to embrace the new reality of hybrid work.

In terms of countries, South Africa saw the highest number of detections in the second quarter of 2022 at 1,400,337 even at a 41% decrease from the previous quarter, followed by Kenya at 566,666 detections and at a 66% decrease and Nigeria with 89,073 detections at a 17% decrease. 

“Remote working comes with security risks and threats and hybrid working is no exception. The fact that employees can access company network anytime from anywhere across devices is a trend to be adopted and adapted to with caution. No doubt companies are trying hard to ensure employees are well-connected to work more collaboratively, and have access to data to meet business needs, but strong and strict security measures need to be in place to avoid any slip-ups. Incorrect RDP setting, weak passwords, or use of public WI-FI can result in serious setbacks,” said Maher Yamout, Senior Security Researcher at Kaspersky.

]]>
https://techeconomy.ng/africa-remote-desktop-protocol-attacks-down-53-in-q2-2022-kaspersky-reports/feed/ 0
Attacker Dwell Time Increased by 36%, Sophos’ Active Adversary Playbook 2022 Reveals https://techeconomy.ng/attacker-dwell-time-increased-by-36-sophos-active-adversary-playbook-2022-reveals/ https://techeconomy.ng/attacker-dwell-time-increased-by-36-sophos-active-adversary-playbook-2022-reveals/#comments Wed, 08 Jun 2022 08:55:28 +0000 https://techeconomy.ng/?p=75955 Sophos, a global leader in next-generation cybersecurity, today released the “Active Adversary Playbook 2022,” detailing attacker behaviors that Sophos’ Rapid Response team saw in the wild in 2021. 

The findings show a 36% increase in attacker dwell time, with a median intruder dwell time of 15 days in 2021 versus 11 days in 2020.

The report also reveals the impact of ProxyShell vulnerabilities in Microsoft Exchange, which Sophos believes some Initial Access Brokers (IABs) leveraged to breach networks and then sell that access to other attackers.

“The world of cybercrime has become incredibly diverse and specialized. IABs have developed a cottage cybercrime industry by breaching a target, doing exploratory reconnaissance or installing a backdoor, and then selling the turn-key access to ransomware gangs for their own attacks,” said John Shier, senior security advisor at Sophos. “In this increasingly dynamic, specialty-based cyberthreat landscape, it can be hard for organizations to keep up with the ever-changing tools and approaches attackers use. It is vital that defenders understand what to look for at every stage of the attack chain, so they can detect and neutralize attacks as fast as possible.”

Sophos’ research also shows that attacker dwell time was longer in smaller organizations’ environments. Attackers lingered for approximately 51 days in organizations with up to 250 employees, while they typically spent 20 days in organizations with 3,000 to 5,000 employees.

Attacker dwell time report by Sophos

“Attackers consider larger organizations to be more valuable, so they are more motivated to get in, get what they want and get out. Smaller organizations have less perceived ‘value,’ so attackers can afford to lurk around the network in the background for a longer period. It’s also possible these attackers were less experienced and needed more time to figure out what to do once they were inside the network. Lastly, smaller organizations typically have less visibility along the attack chain to detect and eject attackers, prolonging their presence,” said Shier. “With opportunities from unpatched ProxyLogon and ProxyShell vulnerabilities and the uprise of IABs, we’re seeing more evidence of multiple attackers in a single target. If it’s crowded within a network, attackers will want to move fast to beat out their competition.”

Additional key findings in the playbook include:

  • The median attacker dwell time before detection was longer for “stealth” intrusions that had not unfolded into a major attack such as ransomware, and for smaller organizations and industry sectors with fewer IT security resources. The median dwell time for organizations hit by ransomware was 11 days. For those that had been breached, but not yet affected by a major attack, such as ransomware (23% of all the incidents investigated), the median dwell time was 34 days. Organizations in the education sector or with fewer than 500 employees also had longer dwell times
  • Longer dwell times and open entry points leave organizations vulnerable to multiple attackers. Forensic evidence uncovered instances where multiple adversaries, including IABs, ransomware gangs, cryptominers, and occasionally even multiple ransomware operators, were targeting the same organization simultaneously
  • Despite a drop in using Remote Desktop Protocol (RDP) for external access, attackers increased their use of the tool for internal lateral movement. In 2020, attackers used RDP for external activity in 32% of the cases analyzed, but this decreased to 13% in 2021. While this shift is a welcome change and suggests organizations have improved their management of external attack surfaces, attackers are still abusing RDP for internal lateral movement. Sophos found that attackers used RDP for internal lateral movement in 82% of cases in 2021, up from 69% in 2020
  • Common tool combinations used in attacks provide a powerful warning signal of intruder activity. For example, the incident investigations found that in 2021 PowerShell and malicious non-PowerShell scripts were seen together in 64% of cases; PowerShell and Cobalt Strike combined in 56% of cases; and PowerShell and PsExec were found in 51% of cases. The detection of such correlations can serve as an early warning of an impending attack or confirm the presence of an active attack
  • Fifty percent of ransomware incidents involved confirmed data exfiltration – and with the available data, the mean gap between data theft and the deployment of ransomware was 4.28 days. Seventy-three percent of incidents Sophos responded to in 2021 involved ransomware. Of these ransomware incidents, 50% also involved data exfiltration. Data exfiltration is often the last stage of the attack before the release of the ransomware, and the incident investigations revealed the mean gap between them was 4.28 days and the median was 1.84 days
  • Conti was the most prolific ransomware group seen in 2021, accounting for 18% of incidents overall. REvil ransomware accounted for one in 10 incidents, while other prevalent ransomware families included DarkSide, the RaaS behind the notorious attack on Colonial Pipeline in the U.S. and Black KingDom, one of the “new” ransomware families to appear in March 2021 in the wake of the ProxyLogon vulnerability. There were 41 different ransomware adversaries identified across the 144 incidents included in the analysis. Of these, around 28 were new groups first reported during 2021. Eighteen ransomware groups seen in incidents in 2020 had disappeared from the list in 2021

“The red flags that defenders should look out for include the detection of a legitimate tool, combination of tools, or activity in an unexpected place or at an uncommon time,” said Shier. “It is worth noting that there may also be times of little or no activity, but that doesn’t mean an organization hasn’t been breached. There are, for instance, likely to be many more ProxyLogon or ProxyShell breaches that are currently unknown, where web shells and backdoors have been implanted in targets for persistent access and are now sitting silently until that access is used or sold.

“Defenders need to be on the alert for any suspicious signals and investigate immediately. They need to patch critical bugs, especially those in widely used software, and, as a priority, harden the security of remote access services. Until exposed entry points are closed and everything that the attackers have done to establish and retain access is completely eradicated, just about anyone can walk in after them, and probably will.”

The Sophos Active Adversary Playbook 2022 is based on 144 incidents in 2021, targeting organizations of all sizes, in a wide range of industry sectors, and located in the U.S., Canada, the U.K., Germany, Italy, Spain, France, Switzerland, Belgium, Netherlands, Austria, the United Arab Emirates, Saudi Arabia, the Philippines, the Bahamas, Angola, and Japan.

The most represented sectors are manufacturing (17%), followed by retail (14%), healthcare (13%), IT (9%), construction (8%), and education (6%).  

The aim of Sophos’ report is help security teams understand what adversaries do during attacks and how to spot and defend against malicious activity on the network. To learn more about attacker behaviors, tools and techniques, read the Sophos Active Adversary Playbook 2022 on Sophos News.

]]>
https://techeconomy.ng/attacker-dwell-time-increased-by-36-sophos-active-adversary-playbook-2022-reveals/feed/ 1