Blog

Hackers Are Now Using Remote Desktop Services For Ransomware

By Mersad • May 2, 2019

Ransomware continues to be the weapon of choice for hackers around the world, but their distribution methods are evolving. Recently, a new strain of the ransomware known as CryptoMix was found in the wild, sporting a new distribution methodology.


Hackers are beginning to target publicly exposed remote desktop services and installing their poisoned software manually.


In the case of the remix of CryptoMix, once installed, the malware appends the .DLL extension to all encrypted files and predictably demands a ransom from the victim to get his or her files back. Despite the evolving delivery method, the threat remains the same, so perhaps it's time for a review.


Here are several things your staff can do to minimize your risk of being taken offline by a ransomware attack:


  • Back your data up religiously. This isn't so much a prevention strategy as it is an insurance policy. It should go without saying, but too many SMBs don't do this, so we wanted to list it first.


  • Make sure your employees are absolutely phobic when it comes to opening attachments from people they don't know and trust. Even in cases where they recognize the sender, it's always best to take the step of phone verification before actually opening the file.


  • All attachments should be scanned with a robust antivirus tool before opening


  • Be sure your people know not to connect Remote Desktop Services directly to the internet. Everyone using such services should do so via a VPN.


  • Make sure all Windows updates and security patches are installed in a timely fashion. Many a problem can be avoided simply by keeping your software up to date.


  • If you're not using some type of security software that relies on behavioral detection or white list technology, you're not doing your company any favors.


None of these things (even taken together) will absolutely ensure that you don't fall victim to a determined hacker, but they will dramatically reduce your risk.


Used with permission from Article Aggregator

Related Posts

By BayPointe Technology • October 7, 2026
Learn what secure remote IT support requires, from trusted help requests and controlled access to device standards, session records, and onsite escalation.
By BayPointe Technology • September 30, 2026
Find out whether your business backups can support recovery. Plan restore tests, measure results, and address gaps before an outage disrupts work.
By BayPointe Technology • September 23, 2026
Help employees recognize phishing emails, verify unusual requests, and report concerns with a practical process for Northeast Ohio businesses.
Stressed man at desk with hand on face, holding glasses near a computer and moving boxes
By BayPointe Technology • September 16, 2026
Recurring IT issues, growing support demands, or unclear security responsibilities? Learn when your Northeast Ohio business should consider managed IT services.
Blue illuminated curved metal structure with repeating ribbed arches
By BayPointe Technology • September 9, 2026
Plan office-move IT tasks, including internet installation, cabling, phones, equipment, vendor coordination, and opening-day readiness checks.

Contact Information

1035 Medina Rd, Suite #800

Medina, OH 44256