Windows Remote Desktop servers hacked for use in DDoS attacks

DDoS Attack
(Image credit: Shutterstock)

Microsoft is the latest major tech firm to find that its resources are being misused as part of a DDoS attack. It has been reported that Windows Remote Desktop Protocol (RDP) servers are being exploited to amplify attacks.

Application and network performance management firm Netscout revealed that attackers are utilizing a new UDP reflection/amplification attack vector built into the Windows RDP service to achieve an amplification ratio of 85.9:1 and peak at ~750 Gbps for their DDoS attacks.

“The collateral impact of RDP reflection/amplification attacks is potentially quite high for organizations whose Windows RDP servers are abused as reflectors/amplifiers,” a Netscout update reads. “This may include partial or full interruption of mission-critical remote-access services, as well as additional service disruption due to transit capacity consumption, state-table exhaustion of stateful firewalls, load balancers, etc. Wholesale filtering of all UDP/3389-sourced traffic by network operators may potentially overblock legitimate internet traffic, including legitimate RDP remote session replies.”

Dealing with disruption

It now appears that the RDP reflection/application vector is being offered as a DDoS-for-hire service, making its way into the hands of threat actors who do not have the skill or inclination to build up their own DDoS infrastructure.

As Netscout mentioned, it is not only the victims of DDoS attacks that are affected by this misuse of Windows RDP servers. 

Organizations that are having their resources exploited in this way can also face disruption. In order to mitigate any damage, businesses can choose to either disable the vulnerable UCP-based service or make the affected servers available only via VPN.

Late last year, it was discovered that cyberattackers had found a way to amplify their DDoS attacks by using Citrix’s ADC networking equipment.

Via Bleeping Computer

Barclay Ballard

Barclay has been writing about technology for a decade, starting out as a freelancer with ITProPortal covering everything from London’s start-up scene to comparisons of the best cloud storage services.  After that, he spent some time as the managing editor of an online outlet focusing on cloud computing, furthering his interest in virtualization, Big Data, and the Internet of Things. 

Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 23 (game #385)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 23 (game #651)
Google Pixel 9 Pro Fold main display opened
Apple is rumored to be prioritizing battery life on the foldable iPhone – which could also feature a liquid metal hinge for added durability
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost