Phishing

Microsoft enhances Windows security against phishing with RDP file protections

Windows 11 start button on computer menu screen close up view

Microsoft has implemented new security measures within Windows to combat phishing attacks that exploit Remote Desktop connection (.rdp) files. These updates introduce warnings and disable risky shared resources by default, aiming to protect users from malicious redirection, with further coverage provided by Bleeping Computer.

RDP files, commonly used in enterprise environments for remote access, have been increasingly abused by threat actors, including the Russian state-sponsored APT29 group. Attackers send malicious RDP files via phishing emails, which, when opened, can silently connect to attacker-controlled systems. These files can then redirect local drives, capture clipboard data, or hijack authentication mechanisms to steal files, credentials, and impersonate users.

The new protections, rolled out with recent Windows cumulative updates, display a one-time educational prompt upon the first opening of an RDP file. Subsequent attempts will trigger a security dialog detailing the remote system's address and any resource redirections, with all options disabled by default. Warnings are also issued for unsigned files.t.

Source: Bleeping Computer

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds