RDP - Tool

Threat entity extracted from intelligence sources

Frequency
9
occurrences
First Seen
November 5, 2025
Last Seen
June 30, 2026

RDP is a tool tracked across 10 threat clusters and 9 intelligence report mentions on ThreatCluster. First observed November 5, 2025; most recent activity June 30, 2026.

Overview

RDP (Remote Desktop Protocol) is a Microsoft protocol that enables remote sessions to Windows systems. In cybersecurity, attackers exploit exposed or poorly protected RDP endpoints, stolen credentials, or vulnerabilities to gain remote access, move laterally, and deploy ransomware or other malware. Its significance stems from wide deployment in enterprises and its frequent use as an initial access vector by ransomware groups, including activity tied to Akira per CISA advisories.

Related Threat Clusters

Recent Intelligence Reports

  • Hydra — www.kali.org · June 30, 2026
  • iOT365 advances OT cybersecurity with multi-vector detection for emerging post — Industrialcyber.Co · June 18, 2026
  • Vortex Werewolf Attacking Organizations to Gain Tor-Enabled Remote Access Over the RDP, SMB, SFTP, and SSH Protocols — Cybersecuritynews · February 9, 2026
  • Zero Networks warns lateral movement eclipses zero-days — Securitybrief · February 4, 2026
  • Rogue ScreenConnect: Common Social Engineering Tactics We Saw in 2025 — Huntress · December 31, 2025
  • Akira Ransomware Group Poses ‘Imminent Threat’ to Critical Infrastructure: CISA — Thecyberexpress · November 13, 2025
  • APT Groups Attacking Construction Industry Networks to Steal RDP, SSH and Citrix Logins — Cybersecuritynews · November 10, 2025
  • APT Groups Target Construction Firms to Steal RDP, SSH, and Citrix Credentials — Gbhackers · November 10, 2025

CVSS v3.1 Breakdown