What is hRDP and why its probably one of the worst malware you could have. (Simple)

Hello everyone,

I'm here to shed some light on a sneaky thing called hRDP, which stands for "Hidden Remote Desktop Protocol". Let me break down what it does in simple terms:

  1. It creates a secret new user on your computer.
  2. It gives this hidden user access to remote desktop connections.
  3. It tweaks a system file (termsrv.dll) to let more than one user log in at once.
  4. It runs a special check (using 'sfc /scanfile') to fix the tweaked file so that regular users won't notice anything's wrong.
  5. It uses some networking tricks to open up ports, which is like making secret doorways into your computer.
  6. It makes sure this new user stays under the radar.

Now, the thing about hRDP is that it's super stealthy. It's not like those typical viruses (RATs) that you can spot and shut down easily. hRDP just sits there quietly, so even your antivirus might not realize there's an extra "user" lurking around.

Wondering if you've got hRDP hiding on your PC? Here's how to check:

  1. Hit "WINDOWS" + "R" to open a little run box.
  2. Type in 'netplwiz' and press enter.
  3. Scan the list for any users that make you go, "Who's that?"
  4. Boot out any strangers from that list.
  5. Pull up the task manager.
  6. Hit the 'Users' tab to see who's hanging out.
  7. If you see names you don't recognize, and they're active, that's a red flag.
  8. Simply select them and hit "sign off."

So why do bad guys use hRDP? Well, some shady characters on the dark web will sneak hRDP onto devices to turn them into remote servers for their dodgy websites, sometimes hosting stuff that's definitely not safe for work — or legal.

This is why hRDP is bad news. It can drag you into trouble without you ever lifting a finger. Stay safe and check your PCs, folks!

Just so you know, hRDP isn't a recent phenomenon, but it's surprising how few people are aware of it. We often hear chatter about RATs and ransomware, but this type of security threat doesn't seem to get the same spotlight.

submitted by /u/tamirawad
[link] [comments]

from hacking: security in practice https://ift.tt/EKqFXkQ

Comments