Blacksec

Administrator
Staff member
ROOT
VIP
Open RDP on the internet is the single most attacked surface in computing — scanners sweep every IPv4 address continuously, brute-force bots hammer port 3389 around the clock, and one weak password becomes the network's front door for ransomware crews. This guide covers why RDP gets hunted, how the attacks run, and the hardening that turns a honeypot back into a tool. Server operators read every word.

TL;DR — Port 3389 exposed = permanent target. Brute force, BlueKeep-class bugs, credential reuse, then lateral movement straight into ransomware. Lock it behind VPN/NLA, strong creds, rate limits, and network layering. Full playbook below.

1. THE OPEN DOOR (KID VERSION)

Kid version: every kid in town knows your house has a spare key hidden under the MAT by the BACK DOOR — and everybody knows WHERE the mat is. You are not just hoping nobody tries it; you are relying on the entire town's good manners while a hundred strangers test that mat hourly.

That mat is exposed RDP. Shodan and Censys index every connected 3389 on the planet — attackers do not even need to scan, they just query the database. Automated botnets (not humans — bots) then attempt thousands of password combinations per hour per target. "Admin/123456", "Administrator/[hostname]", "user/Password1!" — the classics still land because humans still pick them.

The math is grim: internet-exposed RDP gets brute-forced within MINUTES of going live. Honeypot research has shown first login attempts arriving faster than DHCP finishes. There is no "hidden" port — there is only a port nobody has queried yet.

2. THE ATTACK PATHS

Credential brute force. The bread and butter. Lockout policies LOOK like defense until you realize attackers distribute attempts across accounts and time them to avoid thresholds — or spray one common password against thousands of usernames. Slow-lorries beat lockouts. Once in: a full interactive desktop as the authenticated user, and every RDP login leaves forensic gold — but attackers cover tracks with timestomping and log clearing.

Protocol vulnerabilities. BlueKeep (CVE-2019-0708) showed what RDP bugs are worth — wormable, pre-auth, no credentials needed, straight to SYSTEM. DejaBlue variants followed. Old unpatched Windows boxes remain internet-shredded for years after disclosure. Auto-repeat: once one machine falls, internal scanning finds the next unpatched host.

The ransomware pipeline. This is why RDP matters in 2026 headlines: compromised RDP is the NUMBER ONE initial access vector in ransomware intrusions. The chain, documented in a hundred incident reports:

  • Botnet validates working credentials (sold cheap on markets — "RDP logins" is its own product category).
  • Operator logs in manually, drops tooling: Mimikatz or Comsvcs for credential dump, SharpHound for AD mapping.
  • Lateral movement via the harvested admin creds — one RDP session becomes domain-wide.
  • Backup deletion, EDR tampering, ransomware deploy. Network held hostage.

No exploit needed at stage one. The door was already open; everything after is post-authentication tradecraft.

3. HARDENING — THE REAL CHECKLIST

  • Do not expose 3389. Full stop. VPN or SSH tunnel to reach RDP, RDP only on the internal side. WireGuard takes ten minutes and kills the entire scan-and-brute class permanently.
  • Network Level Authentication mandatory. NLA forces authentication BEFORE the session renders — unauthenticated surface shrinks to almost nothing, brute-force attempts terminate pre-session, and it defuses the BlueKeep-style pre-auth bug class.
  • Password policy that survives spraying — 20+ character random per admin account (password manager generated), unique per machine, no shared local admin passwords anywhere. LAPS-style randomization for domain machines.
  • Account lockout + source rate limiting — lockout thresholds paired with firewall-side connection rate limits so distributed attempts die at the network layer, not just the auth layer.
  • Change the port as friction, not security — moving 3389 to 44338 cuts mass-bot noise by orders of magnitude. It is camouflage, keep it as layer 7 of 8, never layer 1.
  • Restrict by source IP — allowlist office/VPN ranges at the firewall. Unknown source, no SYN.
  • Patch the RDP stack monthly — treat KB articles touching RDP/RemoteFX as emergency-tier.
  • Audit and monitor — 4624/4625 logon events, watch for off-hours logins, impossible travel on admin accounts, and RDP session creation followed by log clearing.

4. IF YOU RUN RDP AS A SERVICE

Servers sold with "managed RDP" access need the same treatment plus structure:

LayerControlPurpose
EdgeVPN-only 3389, port randomizationremove from internet scans
AuthNLA + 24-char random + MFA gatekill spray/brute success
Sessionidle timeout, concurrent-session limitsshrink unattended windows
Networksegmentation, admin VLAN, egress filteringcontain a compromised box
Telemetrylog shipping off-box, alerting on 4624 type 10detect the session that got in
Responseprebuilt rebuild image, known-good backupsrecover without paying anyone

Egress filtering deserves the highlight: a compromised RDP box phones home for tooling and C2. Blocking outbound from server VLANs to the wild internet turns a foothold into a dead end. Exfil dies, callbacks die, downloaders fail.

5. FIELD CHEAT SHEET

TaskMove
Find exposed RDPShodan: port:3389 product:"Remote Desktop Services"
Audit your ownTest-NetConnection host -Port 3389 from outside your network
Force NLAregistry: UserAuthentication=1 under Winlogon Terminal Server
Lock the portfirewall allowlist: VPN subnet + office IPs only
Monitor inEvent 4624 LogonType 10, alert off-hours + new sources
Responseisolate, rotate creds from clean machine, rebuild from image

— RELATED GUIDES —

Port behind VPN, NLA enforced, random creds per box, logs shipping off-machine — the honeypot becomes a tool the moment the internet stops seeing it. Run the audit from outside your own network tonight, because the bots already did.
 
Last edited: