Skip to main content
News Directory 3
  • Business
  • Entertainment
  • Health
  • News
  • Sports
  • Tech
  • World
Menu
  • Business
  • Entertainment
  • Health
  • News
  • Sports
  • Tech
  • World
RDP Auth Server Scan Surge: Security Threat Explained - News Directory 3

RDP Auth Server Scan Surge: Security Threat Explained

August 26, 2025 Lisa Park Tech
News Context
At a glance
  • A surge in‍ reconnaissance activity targeting microsoft Remote ⁢Desktop Web Access and RDP Web Client suggests attackers⁤ are ⁤preparing for credential-based attacks, according to internet intelligence firm GreyNoise.
  • Internet intelligence firm GreyNoise detected a substantial increase in scanning activity on February 28, 2024, involving 1,971 IP addresses simultaneously probing Microsoft Remote⁢ Desktop web Access (RD Web)...
  • The⁢ scans ⁣are⁤ designed to⁣ identify timing flaws in the ⁤RDP authentication process.
Original source: bleepingcomputer.com

Coordinated Scanning Campaign targets Microsoft RDP, Signaling Potential Attacks

Table of Contents

  • Coordinated Scanning Campaign targets Microsoft RDP, Signaling Potential Attacks
    • What Happened?
    • How ‍Timing Flaws Work
    • Key ⁢Findings from GreyNoise
    • Potential Impact and Mitigation
      • At a Glance
      • Editor’s Analysis

A surge in‍ reconnaissance activity targeting microsoft Remote ⁢Desktop Web Access and RDP Web Client suggests attackers⁤ are ⁤preparing for credential-based attacks, according to internet intelligence firm GreyNoise.

Febuary 29, 2024

What Happened?

Internet intelligence firm GreyNoise detected a substantial increase in scanning activity on February 28, 2024, involving 1,971 IP addresses simultaneously probing Microsoft Remote⁢ Desktop web Access (RD Web) and RDP Web Client authentication portals. greynoise blog This represents a notable anomaly, as the company typically observes only 3-5 such addresses daily.

The⁢ scans ⁣are⁤ designed to⁣ identify timing flaws in the ⁤RDP authentication process. These flaws could allow‍ attackers⁢ to confirm the validity of usernames, paving the way for subsequent credential-based attacks like brute-force or password-spray attempts.

How ‍Timing Flaws Work

timing flaws exploit subtle differences in system response times. When an RDP server receives a login⁢ attempt, it responds differently depending ⁤on whether the username is valid or invalid. An attacker can‍ measure these response times; a faster response to ⁣a‍ valid username indicates a correct guess. OWASP Top Ten

This technique,while subtle,can‍ be automated to rapidly test numerous usernames,effectively bypassing conventional security measures.

Key ⁢Findings from GreyNoise

GreyNoise’s analysis revealed several key details:

  • Massive Spike: 1,971 IP addresses engaged in coordinated scanning.
  • Client Signature: 1,851 of the scanning ips shared the same client signature.
  • Malicious Reputation: Approximately 92% of⁢ the IPs with the shared signature were ⁣already flagged as⁤ malicious.
  • Geographic ⁤Origin: The majority of the scanning IPs ⁢originated from Brazil.
  • Target Location: The primary ‍targets of the scans were IP addresses located in the united States.

These findings suggest a ⁢single botnet or a coordinated group ‍utilizing a common toolset is responsible for the scans. GreyNoise Blog

Potential Impact and Mitigation

Triumphant exploitation of timing flaws in RDP ⁤could led to:

  • Account takeover: Attackers gaining unauthorized access to systems.
  • Data Breaches: Sensitive details being stolen.
  • Ransomware attacks: Systems being encrypted and held for ransom.

Organizations can ‍mitigate this threat by:

  • Enabling Multi-Factor Authentication (MFA): Adding an extra layer of security beyond passwords.
  • Monitoring RDP Logs: Detecting suspicious login attempts.
  • Patching RDP Systems: Ensuring systems are up-to-date with the latest security patches.
  • Network⁣ Segmentation: Limiting access⁢ to RDP services to only⁢ authorized users and networks.
  • Implementing Account Lockout Policies: Preventing brute-force attacks.

At a Glance

  • What: Coordinated scanning campaign targeting Microsoft RDP.
  • Where: Scanning IPs originating primarily from Brazil, targeting IPs in the United⁣ States.
  • When: detected on February 28, 2024.
  • Why it Matters: Signals potential for ‍credential-based attacks and account takeover.
  • What’s Next: Organizations should review RDP security⁢ configurations and implement mitigation‍ strategies.

Editor’s Analysis

This scanning activity is a concerning indicator of ⁤increased attacker ⁤interest in exploiting vulnerabilities within RDP. The coordinated

Share this:

  • Share on Facebook (Opens in new window) Facebook
  • Share on X (Opens in new window) X

Related reading

  • Edmonton Oilers beat Vancouver Canucks 9-7 despite Marco Rossi’s goals
  • Gov. Shapiro Announces $448 Million for Pennsylvania Internet Grants
  • Apple to Limit Mac Disk Access Due to AI Security Risks (time.news)
  • Why the Social Security COLA Is Announced in October (daybreakwire.com)

Related

Search:

News Directory 3

News Directory 3 catalogs US newspapers, news services, newsstands and digital news outlets across all 50 states. Browse local publishers by city, state, or topic, and follow current headlines linked back to their original sources.

Quick Links

  • Disclaimer
  • Terms and Conditions
  • About Us
  • Advertising Policy
  • Contact Us
  • Cookie Policy
  • Editorial Guidelines
  • Privacy Policy

Browse by State

  • Alabama
  • Alaska
  • Arizona
  • Arkansas
  • California
  • Colorado

© 2026 News Directory 3. All rights reserved.
For contact, advertising, copyright, issues email: office@newsdirectory3.com