It started as one of the most common attack patterns there is: someone exposed a Remote Desktop (RDP) server directly to the internet, and an attacker began systematically guessing passwords against it. Security analysts at Huntress caught the activity through an unusual signal, domain enumeration commands running on the network, and traced it backward to find the login had actually succeeded, one account out of several that were targeted.
How the Attack Unfolded
What the attacker did next was notably unsophisticated in a way that made it easier to catch: rather than using automated credential-hunting tools, they opened Notepad and manually searched through files on the compromised system that looked like they might contain saved passwords. Forensic analysts later reconstructed this activity through the system’s jumplist records, effectively a log of recently opened files, which showed a methodical, manual search through anything password-themed.
Investigators also noticed the compromised account had been logged into from multiple, geographically distributed IP addresses, a signal of shared or rented attacker infrastructure rather than a single individual working alone. Pulling that thread led to something bigger: a network of domains including one directly linked to the Hive and BlackSuit ransomware operations, alongside supporting infrastructure disguised as a legitimate VPN service and other consumer-facing services. Analysts noted the domain naming convention itself echoed language associated with “big game hunting,” industry shorthand for deliberately targeting larger, higher-value organizations for ransomware deployment.
In this case, the network was isolated before ransomware was actually deployed. But the infrastructure uncovered behind it pointed to something worth every business understanding: a functioning marketplace where one group’s entire job is breaking in and selling that access to someone else’s ransomware operation.
Why This Matters If You’re Not a Big Company
The specialization here is the real story. Initial access brokers don’t need to know anything about ransomware, extortion negotiations, or data theft. Their entire business is finding exposed, poorly defended entry points, like an RDP server open to the internet with a guessable password, and selling that foothold to whoever wants it, often a completely separate criminal group running the actual ransomware operation.
That division of labor means an exposed RDP server with weak credentials isn’t just a risk on its own; it’s inventory in someone else’s supply chain, and it will be found by scanning, not by anyone researching your company specifically. Size doesn’t factor into whether a scanner finds an open RDP port. It only factors into what happens after someone buys the access.
What Actually Would Have Stopped This
The starting point is the most straightforward fix in this entire series: RDP should never be directly exposed to the open internet. It should sit behind a VPN or a Zero Trust access solution requiring authentication before RDP is ever reachable at all, with multi-factor authentication on that access layer specifically. That single architectural change removes the exact door this entire chain walked through.
Beyond that, this case is also a good example of logging working exactly as intended, even when it’s noisy. The analysts specifically noted that failed login attempts fill up log channels in large volumes, which can make it tempting to ignore them. Here, that same noisy log data, properly reviewed, was what surfaced the successful compromise and led to the broader infrastructure discovery before ransomware got deployed.
Security Checklist for Your Business
Never expose RDP directly to the internet. Require VPN or Zero Trust access with MFA before RDP is reachable at all.
Use unique, strong passwords and MFA on every remote access point, not just the ones that feel highest-risk.
Actually review failed login patterns, rather than treating high log volume as noise to ignore. A string of failures followed by a success is a specific, detectable pattern.
Isolate quickly on suspicious activity. In this case, network isolation before ransomware deployment was what kept a compromise from becoming an incident.
An exposed RDP server with a weak password isn’t a small risk because it seems old and well-known. It’s exactly the kind of opening a specialized criminal supply chain is built to find and sell. MSP Today’s trusted tech partner is JK Computer Solutions. If you want a second set of eyes on your setup, get in touch.
Source: Huntress, “Brute Force or Something More? Ransomware Initial Access Brokers Exposed”.



