VORANT. Threat Intelligence Sign in Get the full feed

RansomHub Deployed After RDP Password-Spray Intrusion

high threat

RDP password spraying led to credential theft, Rclone data exfiltration, and network-wide RansomHub ransomware deployment via SMB, per DFIR Report analysis.

The DFIR Report detailed a November 2024 intrusion that began with a four-hour password-spray attack against an internet-facing RDP server, ultimately compromising six accounts. After gaining an elevated-token session, the threat actor used living-off-the-land commands (net, nltest, nslookup) alongside Mimikatz and Nirsoft's CredentialsFileView to harvest credentials and interact with LSASS memory, and used Advanced IP Scanner and SoftPerfect NetScan for network discovery. The actor moved laterally via RDP to domain controllers, backup servers, and file servers, eventually establishing persistence through legitimate RMM tools Atera and Splashtop.

On day three, the actor staged Rclone with helper scripts (nocmd.vbs, rcl.bat) to exfiltrate roughly 2.03GB of documents, spreadsheets, emails, and images over SFTP disguised on port 443 to a remote server. After further reconnaissance and password resets across multiple accounts, the actor deployed a RansomHub ransomware binary (amd64.exe) on day six. The malware killed hypervisor VMs, deleted shadow copies, cleared event logs, modified symlink behavior, and propagated network-wide via SMB and remote services before encrypting files and dropping a RansomHub ransom note.

Total time-to-ransomware was approximately 118 hours across six days. The report provides detailed indicators, Sigma/YARA detections, and MITRE ATT&CK mappings, illustrating a typical RansomHub affiliate playbook combining commodity credential-theft tools, legitimate RMM software for stealth persistence, and SMB-based ransomware propagation.

Mentioned in this report

Threat actors RansomHub
Malware MimikatzNirsoft CredentialsFileViewRansomHubRclone

Source reporting: https://thedfirreport.com/2025/06/30/hide-your-rdp-password-spray-leads-to-ransomhub-deployment

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free