Шишинг с Rogue RDP. Используем встроенные средства Windows для проникновения в сеть

Rogue RDP – Revisiting Initial Access Methods - Black Hills Information Security

EDR and XDR have significantly improved the level of protection against phishing. Classic document mailings almost don’t work anymore. As an alternative, Rogue RDP as a delivery tool and Living off the Land Binaries for initial access to the customer’s network is good option.

leverage a malicious RDP server, an RDP relay, and a weaponized .RDP connection file which forces unsuspecting victims into connecting and forwarding control over some parts of their machine.

<aside> ⚠️ Requirements

To implement Rogue RDP, you need to create a Windows machine with a white IP address. Then install WSL (Windows Sub System For Linux) and restart the system

<aside> ⚠️ using signed RDP file to gain more visual legitimacy

</aside>

Preparation Steps

  1. Set up Windows Machine:

  2. Obtain and Set Up SSL Certificate:

  3. Install Certificate on Windows:


RDP File Configuration

  1. Create RDP File:

  2. Sign RDP File:

  3. Check that it is actually signed.

    image.png