RDP를 이용하는 공격 기법 및 사례 분석
2022-10-12 • Ahnlab • Analysis of attack techniques and cases using RDP •
AhnLab explains how attackers use Windows Remote Desktop Protocol for initial access, lateral movement, and persistence after obtaining credentials or enabling remote desktop services. The report cites ransomware and APT cases where attackers used RDP directly, opened firewall rules, enabled the service with scripts, or tunneled RDP through tools such as Plink after compromising servers. It also describes RDP Wrapper abuse, including Kimsuky deployments on AppleSeed-infected systems, and cases where attackers create new local accounts for persistent access. The report frames RDP monitoring, credential hygiene, and remote-access hardening as core controls against enterprise compromise.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 81ee91290a78d2d38b47a7ae25ec717f | 2022-10-12 | 2022-10-12 |
| HASH | b500a8ffd4907a1dfda985683f1de1df | 2022-10-12 | 2022-10-12 |
| HASH | 185bc3037314ec2dbd6591ad72cf08b4 | 2022-10-12 | 2022-10-12 |
| IPv4 | 80.66.76.22 | 2022-10-12 | 2022-10-12 |