November 21, 2017 By Douglas Bonderud 2 min read

Small businesses are prime targets for malware. According to eSecurity Planet, small and midsized businesses (SMBs) lost $75 billion to ransomware attacks last year. These businesses are also caught in the crosshairs for new and evolving malware strains, since they often lack the IT staff and security controls necessary to detect and combat threats.

Ransomware Attacks Target SMBs

According to Naked Security, the largest company targeted by recent remote desktop protocol (RDP) attacks had 120 people and the smallest had fewer than 30. The attack methodology wasn’t exactly complex: Cybercriminals used publicly available tools to scan for internet-facing remote desktop ports. They then leveraged commonly used passwords to crack weak security and gain access.

Once behind IT defenses, attackers made their own admin accounts to ensure that backup access points were still available even if IT staff closed the initial security loopholes. Then it was just a matter of installing software to tweak antimalware applications and elevating privileges using known vulnerabilities before the cybercriminals deployed ransomware attacks and demanded one bitcoin in payment.

Good News and Bad News

The good news? Attackers haven’t seen much profit. The not-so-good news? RDP attacks remain a huge problem for companies — and SMBs in particular.

Consider the recent attacks: Cybercriminals needed zero finesse and barely any effort to crack stock-permission RDP access points and create persistent admin accounts. This gave them the time and space to adjust system settings and prime networks for malware delivery, all while SMB owners and staff were blissfully unaware.

RDP attacks aren’t a new thing; enterprises have been enduring them for years. However, SMBs are especially vulnerable to these attacks because their security staff are often juggling multiple jobs. Rather than focusing purely on security, these teams tend to spend most of their time trying to keep IT up and running. This gives cybercriminals the ideal opening.

All Is Not Lost

The better news? It’s not impossible to prevent RDP attacks. The easiest way to avoid an attack is to shut this service down. Unless SMBs have remote workers using RDP connections daily, the insecurity of stock permissions on internet-facing ports puts companies at risk.

If your business regularly requires RDPs, start by changing the passwords and then watch all admin accounts. If something doesn’t seem right, it’s probably not. It’s better to suspend remote desktop access than to fall victim to a ransomware infection.

Malware-makers love SMBs, and RDP ransomware attacks are often a perfect match for low-motivation cybercriminals looking for an easy mark. Make it harder for cyberattackers by changing passwords right now, monitoring admin accounts and being prepared to shut down RDP on demand.

More from

What we can learn from the best collegiate cyber defenders

3 min read - This year marked the 19th season of the National Collegiate Cyber Defense Competition (NCCDC). For those unfamiliar, CCDC is a competition that puts student teams in charge of managing IT for a fictitious company as the network is undergoing a fundamental transformation. This year the challenge involved a common scenario: a merger. Ten finalist teams were tasked with managing IT infrastructure during this migrational period and, as an added bonus, the networks were simultaneously attacked by a group of red…

A spotlight on Akira ransomware from X-Force Incident Response and Threat Intelligence

7 min read - This article was made possible thanks to contributions from Aaron Gdanski.IBM X-Force Incident Response and Threat Intelligence teams have investigated several Akira ransomware attacks since this threat actor group emerged in March 2023. This blog will share X-Force’s unique perspective on Akira gained while observing the threat actors behind this ransomware, including commands used to deploy the ransomware, active exploitation of CVE-2023-20269 and analysis of the ransomware binary.The Akira ransomware group has gained notoriety in the current cybersecurity landscape, underscored…

New proposed federal data privacy law suggests big changes

3 min read - After years of work and unsuccessful attempts at legislation, a draft of a federal data privacy law was recently released. The United States House Committee on Energy and Commerce released the American Privacy Rights Act on April 7, 2024. Several issues stood in the way of passing legislation in the past, such as whether states could issue tougher rules and if individuals could sue companies for privacy violations. With the American Privacy Rights Act of 2024, the U.S. government established…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today