This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

How Unparalleled RDP Monitoring Reveal Attackers’ Tradecraft

Download resources

About this session

Olivier Bilodeau and Andréanne Bergeron, GoSecure security researchers presenting their Black Hat and DefCon 2023 talk, share findings from three years of RDP honeypots built on their open-source tool PyRDP, which intercepts and records every RDP session like a surveillance camera. Analyzing over 190 million events, 2,500 successful logins and roughly 2,300 recorded sessions, they classify attackers into five Dungeons-and-Dragons-themed archetypes: rangers who quietly reconnoiter systems for others, thieves who monetize access through proxyware, crypto mining and fraud, barbarians who brute-force their way into more systems with tools like NLBrute and Masscan GUI, file-less wizards who pivot through compromised hosts, and bards who use the access for mundane tasks like searching for porn, likely bought from an initial access broker. They show session recordings revealing attackers working in teams, communicating in Arabic, Farsi and other languages, and translating error messages, and close with concrete blue-team advice: don't expose RDP externally, rename default administrator accounts, rate-limit connections, and consume the IOCs and Sigma rules they plan to publish.

Key takeaways

  • Never expose RDP directly to the internet; it is the second most common ransomware infection vector after phishing.
  • Rename default administrator-style accounts on gold images; the honeypot data shows nearly all brute-force attempts target 'administrator' and its common-language variants.
  • Enforce strong, unique passwords and rate-limit inbound and outbound connections to slow brute-forcing tools like NLBrute and Masscan GUI.
  • Block outbound RDP from DMZ systems to prevent file-less lateral pivoting through already-compromised hosts, the technique used by the most skilled attacker class observed.
  • Deploy your own RDP honeypots using open-source tooling (PyRDP) and consume published IOCs and Sigma rules to catch this activity before it turns into ransomware.

Speakers

Andréanne Bergeron
Andréanne Bergeron
PhD Cybersecurity Researcher · GoSecure
Andréanne Bergeron, Ph.D., is the director of research at GoSecure, specializing in online attackers' behaviors. Her expertise delves into the intersection of criminology and cybersecurity. In addition, Andréanne holds an esteemed position as an… Read moreRead less

Andréanne Bergeron, Ph.D., is the director of research at GoSecure, specializing in online attackers' behaviors. Her expertise delves into the intersection of criminology and cybersecurity. In addition, Andréanne holds an esteemed position as an affiliated professor in the Department of Criminology of Montreal University, bridging academia and industry. Involved in the cybersecurity community, she is a board member of the Canadian Cybersecurity Network and the co-VP of engagement and outreach for Northsec.

Olivier Bilodeau
Olivier Bilodeau
Cybersecurity Research Director · GoSecure
Olivier Bilodeau, chercheur principal chez Flare, possède plus de 12 ans d’expertise de pointe en cybersécurité, notamment dans les opérations de honeypots, la rétroingénierie de logiciels malveillants et l’interception de RDP. Communicateur… Read moreRead less

Olivier Bilodeau, chercheur principal chez Flare, possède plus de 12 ans d’expertise de pointe en cybersécurité, notamment dans les opérations de honeypots, la rétroingénierie de logiciels malveillants et l’interception de RDP. Communicateur passionné, Olivier a présenté lors de conférences telles que AtlSecCon, BlackHat, DEFCON, SecTor, Derbycon, et bien d’autres. Très impliqué dans sa communauté, il coorganise MontréHack, est président de NorthSec, et anime son Hacker Jeopardy.

Resources

Tags

More from GoSec 2023

Also from Andréanne Bergeron

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.