Skip to main content

GoldBrute Worm

GoldBrute is a newly observed worm targeting exposed Remote Desktop Protocol (RDP) servers worldwide for enrolment into a botnet of the same name.

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

GoldBrute is a newly observed worm targeting exposed Remote Desktop Protocol (RDP) servers worldwide for enrolment into a botnet of the same name.


Threat details

GoldBrute will identify target servers by scanning random IP addresses, with each identified target sent back to a single command and control server via an AES encrypted WebSocket connection. Once it has discovered 80 potential targets, GoldBrute will then begin it's brute-force phase. Each individual GoldBrute bot will only attempt one username and passcode combination per target, likely in an effort to reduce detection as every authentication attempt will originate from a different IP address. Any successful attempt will result in GoldBrute downloading and extracting a ZIP archive containing itself to the affected server.

At the time of publication, it is unclear what the GoldBrute botnet's purpose is beyond its own growth.


Remediation steps

Type Step

If RDP is not used, then ensure port 3389 (TCP/UDP) is blocked at your internet firewall. If RDP is used, then:

  • Ensure network level authentication is enabled.
  • Only allow access for authorised RDP users.
  • Enforce strong password policies.
  • Enforce multi-factor authentication.
  • Don't allow RDP access for privileged user accounts.
  • Don’t use generic accounts.
  • Set user accounts with an expiry date.
  • Audit user accounts periodically.
  • Only allow point-to-point connections from specific IP addresses where feasible.
  • Ensure Transport Layer Security (TLS) is up-to-date.
  • Log and monitor all RDP activity and investigate unusual behaviour.
  • Consider only allowing RDP for authorised virtual private network (VPN) connections.

Additionally, to prevent and detect an infection, ensure that:

  • A robust program of education and awareness training is delivered to users to ensure they don’t open attachments or follow links within unsolicited emails.
  • All operating systems, anti-virus and other security products are kept up-to-date.
  • Regular anti-virus and security scans are performed on your organisation’s estate.
  • All day-to-day computer activities such as email and internet are performed using non-administrative accounts.
  • Strong password policies are in place.
  • Network, proxy and firewall logs should be monitored for suspicious activity.
  • User accounts accessed from affected devices should be reset on a clean computer.
  • Your organisation adopts a holistic all-round approach to Cyber Security as advocated by the 10 Steps to Cyber Security.

Last edited: 14 February 2020 2:44 pm