Remote desktop connections are so powerful a magnet for hackers that an exposed connection can average more than 37,000 times every day from various IP addresses.
During this phase, the attacks are automated. But once they get the right access credentials, the hackers start searching for important or sensitive files manually
An experiment using high-interaction honeypots with an RDP connection accessible from the public web shows how relentless attackers are
@ecksmc 👍🏿 I remember sitting in my company's engineering lab late one night and noticed the comm panel. There were Tx/Rx diodes blinking and I wondered if all of them were friendlies.
@ecksmc it blows my mind every time I hear of someone just, like, directly exposing port 3389 to the internet..
..just wild