While we have previously written on the now infamous XPan ransomware family, some of it’s variants are still affecting users primarily located in Brazil. Harvesting victims via weakly protected RDP (remote desktop protocol) connections, criminals are manually installing the ransomware and encrypting any files which can be found on the system.
Interesti
Malware researchers from Kaspersky have spotted the TeamXRat gang spreading a new ransomware in Brazil via RDP brute-force attacks.
Cyber criminals are using stolen or weak remote desktop credentials to access systems and deliver file-encrypting ransomware.
This is not a novelty in the criminal ecosystem, in March experts discovered a ransomware dubbed Surpr