Skip to content
BreachPathAttack Path LibraryStart
IntermediateRansomware

Exposed remote desktop to ransomware

An internet-exposed remote desktop service with weak authentication gives direct interactive access to a host, which is used to spread, escalate and deploy ransomware.

Technologies
On-premises Active Directory
Entry points
Exposed remote access, Stolen credentials
Sectors
Manufacturing, Retail, Healthcare
Stages
3
01

Exposed remote desktop is accessed

A remote desktop service is reachable from the internet and protected only by a password. Using guessed or reused credentials, the attacker logs in and gains an interactive session on the host.

Attacker objective

Log in interactively to an internet-exposed remote desktop host.

Controls that should stop this
  • Remove direct internet exposure of remote desktop; require VPN + MFA or a gateway
  • Account lockout and strong, unique credentials
  • Geo/IP restrictions and network-level authentication
What defenders should see
  • Remote-desktop logon attempts and successes from external IPs
  • Brute-force / spraying patterns against the service
  • Interactive logon at unusual times
What a pentest validates
  • External assessment identifying exposed remote-desktop services
  • Test credential strength and lockout behaviour
  • Review exposure and gateway/MFA controls
Business impact

The attacker has hands-on-keyboard access to a system inside the network.

02

The attacker escalates and spreads

From the initial host, the attacker harvests credentials, disables protections where possible, and moves to further systems, seeking the privilege needed to affect many machines at once.

Attacker objective

Gain privilege and reach across additional hosts.

Controls that should stop this
  • Segmentation limiting host-to-host remote desktop
  • Least privilege and credential-theft protections
  • Endpoint detection with tamper protection
What defenders should see
  • Internal remote-desktop connections between workstations/servers
  • Credential-access and defence-evasion alerts
  • Disabling of security tooling
What a pentest validates
  • Assumed-breach test from a single compromised host
  • Validate internal segmentation of remote desktop
  • Test endpoint tamper protection and detection
Business impact

The attacker gains the reach and privilege to affect many systems.

03

Ransomware is deployed

The attacker targets backups and recovery, then deploys encryption across the reachable estate, often after quietly staging data for extortion.

Attacker objective

Impair recovery and encrypt broadly for maximum leverage.

Controls that should stop this
  • Immutable, offline backups tested for restore
  • Application control and mass-file-change alerting
  • Isolation of backup infrastructure from general access
What defenders should see
  • Shadow-copy deletion and backup tampering
  • Mass file-modification / encryption behaviour
  • Rapid multi-host activity
What a pentest validates
  • Confirm backups survive a host compromise and spread
  • Test detection of recovery inhibition and mass encryption
  • Validate segmentation limits blast radius
Business impact

Systems are encrypted and recovery impaired — outage, cost and extortion pressure.

ATT&CK techniques in this chain

If this chain completes

A classic, high-frequency ransomware entry route: one exposed remote-desktop host becomes interactive access to the estate, ending in encryption and operational outage.

Should you test this against your environment?

Turn this chain into a scoped red-team brief — objective, systems and identities in scope, testing assumptions and the questions to answer before commissioning.