Cyber-criminals are abusing remote desktop protocol (RDP) – a common method for establishing remote access on Windows systems – in 90% of attacks, according to a new report from Sophos.
The security solutions provider released an Active Adversary analysis which analysed over 150 incident response cases handed by Sophos in 2023.
The report detailed the rise of the RDP frontier in cyber-crime, with 2023 seeing the highest incidence of RDP abuse since Sophos began its active adversary reports in 2021.
In addition, external remote services such as RDP were the most common vector by which attackers initially breached networks; they were the method of initial access in 65% of IR cases in 2023.
External remote services have consistently been the most frequent source of initial access for cyber-criminals since the Active Adversary reports were launched in 2020, and defenders should consider this a clear sign to prioritise the management of these services when assessing risk to the enterprise.
“External remote services are a necessary, but risky, requirement for many businesses. Attackers understand the risks these services pose and actively seek to subvert them due to the bounty that lies beyond. Exposing services without careful consideration and mitigation of their risks inevitably leads to compromise. It doesn’t take long for an attacker to find and breach an exposed RDP server, and without additional controls, neither does finding the Active Directory server that awaits on the other side,” said John Shier, field CTO, Sophos.
In one Sophos X-Ops customer case, attackers successfully compromised the victim four times within six months, each time gaining initial access through the customer’s exposed RDP ports.
Once inside, the attackers continued to move laterally throughout the customer’s networks, downloading malicious binaries, disabling endpoint protection, and establishing remote access.
Compromised credentials and exploiting vulnerabilities are still the two most common root causes of attacks. However, the 2023 Active Adversary Report for Tech Leaders, released last August, found that in the first half of that year, for the first time, compromised credentials surpassed vulnerabilities as the most frequent root cause of attacks.
This trend continued through the rest of 2023, with compromised credentials representing the root cause of over 50% of IR cases for the entire year. When looking at Active Adversary data cumulatively over the years from 2020 through 2023, compromised credentials were also the number one “all-time” root cause of attacks, involved in nearly a third of all IR cases.
Yet despite the historical prevalence of compromised credentials in cyberattacks, in 43% of IR cases in 2023, organisations did not have multi-factor-authentication configured.
Exploiting vulnerabilities was the second most common root cause of attacks, both in 2023 and when analysing data cumulatively from 2020 through 2023, accounting for the root cause in 16% and 30% of IR cases, respectively.
Recommended reading
- What is the Current Data Telling Us About Cyber-attacks?
- Strong Cybersecurity Key to AI Superpower Ambitions, Microsoft Says
- 75% of UK Businesses Had a Cyber Incident Last Year
“Managing risk is an active process. Organisations that do this well experience better security situations than those that don’t in the face of continuous threats from determined attackers. An important aspect of managing security risks, beyond identifying and prioritising them, is acting on the information,” said Shier.
“Yet, for far too long, certain risks such as open RDP continue to plague organisations, to the delight of attackers who can walk right through the front door of an organisation. Securing the network by reducing exposed and vulnerable services and hardening authentication will make organisations more secure overall and better able to defeat cyberattacks.”





