CISA – Cybersecurity and Infrastructure Security Agency recently published an article alerting government and tech sectors of a new phishing email being circulated in the community. This is a large-scale spear-phishing campaign targeting various sectors, including government and IT. The attackers are posing as trusted entities and sending emails with malicious Remote Desktop Protocol (RDP) files. These files allow the attackers to access and control the target’s network, potentially deploying harmful code to maintain access.
Attackers are sending spear-phishing emails with malicious RDP files. In order to access the RDP file, you are entering in your IP Address and Username and often saving the file on your desktop. Once these files are executed, attackers can access and control the network, leading to further malicious activities. Because the file remains on your desktop it can be accessed at anytime leading to stolen data.
Here are some actionable items to use in your business to prevent access to a hacker:
Please report any suspicious activity immediately! Attitude IT urges users and administrators to remain vigilant against spear-phishing attempts, hunt for any malicious activity, report positive findings to Attitude IT, and review the following articles for more information:
If you have any questions or need assistance, please do not hesitate to reach out to our team!