This attack is the ultimate form of Remote Desktop Protocol (RDP) compromise. RDP is one of the most common ways to deploy ransomware because cybercriminals can compromise administrator accounts and systems that control entire organizations. As CrySis encrypts a computer, it also removes all of the automatic backups, so users can’t use them to restore files. Inception: First detected in February 2016; took a few months to spread; Attack vector: Remote Desktop Protocol (RDP)

LeVar Battle

About the Author

LeVar Battle

Senior Communications Manager

LeVar Battle has produced content for healthcare and technology for more than 10 years. He is now a corporate communications and social media manager for Webroot leading the blog editorial and social media team.