DiscoverThe Defender's Advantage PodcastWindows Remote Desktop Protocol: Remote to Rogue
Windows Remote Desktop Protocol: Remote to Rogue

Windows Remote Desktop Protocol: Remote to Rogue

Update: 2025-04-14
Share

Description

Host Luke McNamara is joined by GTIG Senior Security Researcher Rohit Nambiar to discuss Rohit's recent blog on some interesting usage of RDP by UNC5837. Rohit covers the discovery of the campaign, and the novel functionalities they were using to likely support cyber espionage goals. He delves into these findings and the usage of RemoteApps and victim file mapping via RDP, and closes with some of the mysteries that remain about this activity. 

https://cloud.google.com/blog/topics/threat-intelligence/windows-rogue-remote-desktop-protocol

Comments 
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

Windows Remote Desktop Protocol: Remote to Rogue

Windows Remote Desktop Protocol: Remote to Rogue

Mandiant