ZeroHour
Akamai Blogpublished ()ingested Daniel Goldberg

The Oracle of Delphi Will Steal Your Credentials

mediumMalware exploited in the wildimportance 42
AI summary · glm-5.3-flash

Akamai honeypots reveal attackers brute-forcing RDP credentials to download and execute a previously undetected malware family named Trojan.sysscan.

Akamai's deception technology rerouted intruders into honeypots, revealing attacks that brute-force passwords for RDP credentials to access victims. Once connected, the attackers download and execute a previously undetected malware family that Akamai named Trojan.sysscan. The intrusions target exposed RDP services through opportunistic credential guessing.

  • Attackers brute-force passwords to obtain RDP credentials
  • Previously undetected malware family named Trojan.sysscan
  • Deception technology redirects intruders into honeypots
  • Victim systems download and execute the new trojan
VendorsAkamai
OrganizationsAkamai
Full article

Our deception technology is able to reroute attackers into honeypots, where they believe that they found their real target. The attacks brute forced passwords for RDP credentials to connect to the victim download and execute a previously undetected malware, which we named Trojan.sysscan.

The full text could not be extracted from this site (paywall, bot protection or heavy scripting). Read it at akamai.com.