Skip to main content

Hackers can purchase government login credentials for cheap on the dark web

McAfee’s Advanced Threat Research team recently discovered that hackers have access to many organizations that have weak credentials when using Microsoft’s Remote Desktop component in Windows-based systems. Access to these organizations — whether it’s an airport, a hospital or the U.S. government — can be bought for little money through specific shops on the dark web.

Microsoft’s Remote Desktop Protocol (RDP) essentially allows you to connect and use a Windows-based PC from a remote location. When those login credentials are weak, hackers can use brute force attacks to gain the username and password for each connection. McAfee found connections up for sale across various RDP shops on the dark web ranging between a mere 15 to a staggering 40,000 connections.

Recommended Videos

“The advertised systems ranged from Windows XP through Windows 10,” says John Fokker, McAfee’sHead of Cyber Investigations. “Windows 2008 and 2012 Server were the most abundant systems, with around 11,000 and 6,500, respectively, for sale. Prices ranged from around $3 for a simple configuration to $19 for a high-bandwidth system that offered access with administrator rights.”

Among the list of devices, services and networks on the menu are multiple government systems on sale worldwide, including those linked to the United States. The team found connections to a variety of healthcare institutions including medical equipment shops, hospitals, and more. They even found access to security and building automation systems at a major international airport selling for a mere $10.

The problem doesn’t just revolve around desktops, laptops, and servers. Internet of Things devices based on Windows Embedded are also on the menu such as point-of-sale systems, kiosks, parking meters, thin client PCs and more. Many are overlooked and not updated, making them a quiet entryway for hackers.

Black market sellers gain RDP credentials by scanning the internet for systems that accept RDP connections, and then use tools like Hydra, NLBrute and RDP Forcer to attack the login using stolen credentials and password dictionaries. Once they successfully log into the remote PC, they don’t do anything but put the connection details up for sale.

After hackers pay for a connection, they can bring a corporation down to its knees. For instance, a hacker could pay a mere $10 for a connection, infiltrate the network to encrypt the files of every PC, and demand a $40,000 ransom. Compromised PCs can also be used to deliver spam, misdirect illegal activity and mine cryptocurrency. Access is also good for stealing personal information and company trade secrets.

“We found a newly posted Windows Server 2008 R2 Standard machine on the UAS Shop,” Fokker writes. “According to the shop details, it belonged to a city in the United States and for a mere $10 we could get administrator rights to this system. UAS Shop hides the last two octets the of the IP addresses of the systems it offers for sale and charges a small fee for the complete address.”

The solution, according to McAfee, is that organizations need to do a better job at checking all their virtual “doors and windows” so hackers can’t sneak in. Remote access should be secure and not easily exploitable.

Kevin Parrish
Former Digital Trends Contributor
Kevin started taking PCs apart in the 90s when Quake was on the way and his PC lacked the required components. Since then…
A foldable screen laptop to rival the ThinkPad X1 Fold is set to launch soon
Lenovo ThinkPad X1 Fold 2023 left side view showing ports.

Huawei's upcoming event is set to debut its Nova 14 series of smartphones, but it's also unveiling the Huawei MateBook Fold Ultimate Design, a laptop with a foldable screen similar to the Lenovo ThinkPad X1 Fold or the Asus Zenbook 17 Fold. The news comes from the Huawei Terminal account on Weibo, and the event will be held on May 19 at 2:30 PM CST.

The machine is being made in collaboration with Hongmeng Computers. Unfortunately, Huawei remained tight-lipped about further details, but given that the event is in four days, it makes sense. The MateBook Fold Ultimate Design isn't the first laptop to hit the market with a foldable screen, and we can glean some idea of how it will likely operate based on existing models.

Read more
iBuyPower Memorial Day sale: Access huge savings on gaming PCs with this code
The side view of the iBuyPower RDY Y70 R05 gaming PC.

Memorial Day is just around the corner, and iBuyPower is celebrating it with lowered prices for its wide range of gaming PCs. From now until May 26, you can enjoy discounts for the brand's pre-built (RDY) and custom gaming desktops by using the coupon code MEMORIAL during the checkout process. You'll get $50 off for purchases over $999, $100 off for purchases over $1,999, $200 off for purchases over $2,999, and $300 off for purchases over $3,999.

The coupon code during the iBuyPower Memorial Day Mega-Sale will further reduce any promotional prices, so here's your chance at huge savings. Feel free to take a look at all the available offers, but we've also rounded up our favorite gaming PC deals from iBuyPower below if you want any recommendations. Either way, you better hurry -- there's a lot of time left on these discounts, but stocks of the gaming desktop that you've got your eyes on may not last until the sale's last minute.

Read more
The massive Samsung Odyssey G9 is almost half off today
The Samsung Odyssey OLED G9 gaming monitor.

Your powerful gaming PC will be wasted if you're still using an old screen, so you should take advantage of monitor deals for gamers. Here's one from Samsung that you wouldn't want to miss: the 49-inch Samsung Odyssey OLED G9 gaming monitor for $1,300, following a $900 discount on its original price of $2,200. You won't always get the chance to buy a premium display for nearly half-price, so stop hesitating and push forward with your purchase as soon as possible.

Why you should buy the 49-inch Samsung Odyssey OLED G9 gaming monitor

Read more