Microsoft has implemented new security measures within Windows to combat phishing attacks that exploit Remote Desktop connection (.rdp) files. These updates introduce warnings and disable risky shared resources by default, aiming to protect users from malicious redirection, with further coverage provided by Bleeping Computer.RDP files, commonly used in enterprise environments for remote access, have been increasingly abused by threat actors, including the Russian state-sponsored APT29 group. Attackers send malicious RDP files via phishing emails, which, when opened, can silently connect to attacker-controlled systems. These files can then redirect local drives, capture clipboard data, or hijack authentication mechanisms to steal files, credentials, and impersonate users.The new protections, rolled out with recent Windows cumulative updates, display a one-time educational prompt upon the first opening of an RDP file. Subsequent attempts will trigger a security dialog detailing the remote system's address and any resource redirections, with all options disabled by default. Warnings are also issued for unsigned files.t.Source: Bleeping Computer
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds




