---
title: New Alert From CISA- Beware of Spear-Phishing Emails With Malicious RDP Files
description: New phishing campaign targets government and IT sectors with malicious RDP files. Learn prevention strategies and safeguard your network from these spear-phishing attacks.
image: https://www.attitudeit.ca/hubfs/AI-Generated%20Media/Images/phishing%20email.jpeg
---

[Go Back Up](https://www.attitudeit.ca/the-attitude-it-today/new-alert-from-cisa-beware-of-spear-phishing-emails-with-malicious-rdp-files#top)

[Skip to Content](https://www.attitudeit.ca/the-attitude-it-today/new-alert-from-cisa-beware-of-spear-phishing-emails-with-malicious-rdp-files#body)

[![Attitude IT: Keeping Your Technology on Course](https://www.attitudeit.ca/hubfs/Attitude%20IT%20on%20course%20white%20(1100%20%C3%97%20250%20px)-1.svg "Attitude IT: Keeping Your Technology on Course")](https://attitudeit.ca)

Toggle Menu

- [Home](https://www.attitudeit.ca)
- [FAQ](https://www.attitudeit.ca/attitude-it-faq)
- Contact
  
  Toggle children for Contact
  
   Main Menu (Press to Return) 
  
  \> Contact 
  
    - [About](https://www.attitudeit.ca/about-attitude-it)
    - [Contact Us](https://www.attitudeit.ca/contact)
    - [Our Team](https://www.attitudeit.ca/our-team)
    - [Join Our Team](https://www.attitudeit.ca/join-our-team)
- Services
  
  Toggle children for Services
  
   Main Menu (Press to Return) 
  
  \> Services 
  
    - [Cybersecurity](https://www.attitudeit.ca/cybersecurity)
    - [IT Services](https://www.attitudeit.ca/it-services-attitude-it)
    - [Recovery & Backup](https://www.attitudeit.ca/backups)
    - [Data Compliance](https://www.attitudeit.ca/compliance)
- Industries
  
  Toggle children for Industries
  
   Main Menu (Press to Return) 
  
  \> Industries 
  
    - [Manufacturing](https://www.attitudeit.ca/manufacturing-it-ontario)
    - [Construction](https://www.attitudeit.ca/construction-it-ontario)
    - [Accounting IT Services](https://www.attitudeit.ca/accounting-it-services-in-ontario)
- [Blog](https://www.attitudeit.ca/the-attitude-it-today)

- [905-432-7751](tel:19054327751)
- Open Search
  
  Search
  
  Submit Search

# New Alert From CISA- Beware of Spear-Phishing Emails With Malicious RDP Files

[Cybersecurity](https://www.attitudeit.ca/the-attitude-it-today/tag/cybersecurity) Dec 10, 2024, 10:00:00 AM [Attitude IT](https://www.attitudeit.ca/the-attitude-it-today/author/attitude-it) 3 min read

![phishing email](https://www.attitudeit.ca/hs-fs/hubfs/AI-Generated%20Media/Images/phishing%20email.jpeg?width=1000&name=phishing%20email.jpeg)

<https://twitter.com/intent/tweet/?text=New+Alert+From+CISA-+Beware+of+Spear-Phishing+Emails+With+Malicious+RDP+Files&url=https%3A%2F%2Fwww.attitudeit.ca%2Fthe-attitude-it-today%2Fnew-alert-from-cisa-beware-of-spear-phishing-emails-with-malicious-rdp-files> <https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.attitudeit.ca%2Fthe-attitude-it-today%2Fnew-alert-from-cisa-beware-of-spear-phishing-emails-with-malicious-rdp-files> <https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.attitudeit.ca%2Fthe-attitude-it-today%2Fnew-alert-from-cisa-beware-of-spear-phishing-emails-with-malicious-rdp-files> [mailto:?subject=New%20Alert%20From%20CISA-%20Beware%20of%20Spear-Phishing%20Emails%20With%20Malicious%20RDP%20Files&body=https%3A%2F%2Fwww.attitudeit.ca%2Fthe-attitude-it-today%2Fnew-alert-from-cisa-beware-of-spear-phishing-emails-with-malicious-rdp-files](mailto:?subject=New%20Alert%20From%20CISA-%20Beware%20of%20Spear-Phishing%20Emails%20With%20Malicious%20RDP%20Files&body=https%3A%2F%2Fwww.attitudeit.ca%2Fthe-attitude-it-today%2Fnew-alert-from-cisa-beware-of-spear-phishing-emails-with-malicious-rdp-files)

CISA – Cybersecurity and Infrastructure Security Agency recently published an article alerting government and tech sectors of a new phishing email being circulated in the community. This is a large-scale spear-phishing campaign targeting various sectors, including government and IT. The attackers are posing as trusted entities and sending emails with malicious Remote Desktop Protocol (RDP) files. These files allow the attackers to access and control the target’s network, potentially deploying harmful code to maintain access. 

Attackers are sending spear-phishing emails with malicious RDP files. In order to access the RDP file, you are entering in your IP Address and Username and often saving the file on your desktop. Once these files are executed, attackers can access and control the network, leading to further malicious activities. Because the file remains on your desktop it can be accessed at anytime leading to stolen data.

 

**Here are some actionable items to use in your business to prevent access to a hacker:**

1. **Restrict Outbound RDP Connections:** 
     - Block or significantly limit outbound RDP connections to external networks.
     - Implement firewalls with secure policies and access control lists.
2. **Block RDP Files in Communication Platforms:** 
     - Prevent RDP files from being sent through email and webmail services.
     - Block the execution of RDP files by users.
3. **Enable Multi-Factor Authentication (MFA):** 
     - Use MFA wherever possible to add an extra layer of security.
     - *Avoid SMS-based* MFA due to its vulnerability to SIM-jacking.
4. **Adopt Phishing-Resistant Authentication Methods:** 
     - Deploy solutions like FIDO (Fast Identity Online) Authentication tokens to resist phishing attacks.
     - Implement Conditional Access Policies to ensure only authorized users access sensitive systems.
5. **Deploy Endpoint Detection and Response (EDR):** 
     - Use EDR solutions to monitor and respond to suspicious activities and run reports frequently
     - Consider additional security measures like anti-phishing and antivirus solutions. And zero-trust applications and policies.
6. **Conduct User Education:** 
     - Educate users on identifying and reporting phishing emails.
     - Promote awareness of simple tips to avoid phishing.
     - Create a safe reporting environment.
7. **Hunt for Malicious Activity:** 
     - Use indicators from relevant articles to search for malicious activity within your network.
     - Check for unexpected or unauthorized outbound RDP connections over the past year.

Please report any suspicious activity immediately! Attitude IT urges users and administrators to remain vigilant against spear-phishing attempts, hunt for any malicious activity, report positive findings to Attitude IT, and review the following articles for more information:

- Recognize and Report Phishing: [Avoid phishing with these simple tips](https://pn394.keap-link014.com/v2/click/ac817b9dc4594069c2b77ec964074af2/eJyNkMFqwzAMht9F57hZnOzQ3EopJaTrYWznYWKRmGaysJWGruTd526jpw121f_p-5GuIEiGpLFQA1O5riCDgJ1jhyRbT2K6r7Cs9FpnMDo67YOfGOrrb6v3_DYtikddZSAXxoS8PG-2bXPcvx2aY5tQNiFV_MdTPuii0HfR7mnTHGBZ_jTju5PdOckj1BImvF1kXbpKXsOY-EGEY53n8zyvOhfNqvfnPGI3BVR-Cmr2YbR54n1P7gOVIasCsg-ieHBxcNSnFsOMZH9e1OLlu2v5BFPlb9Y=)
- Microsoft: [Midnight Blizzard conducts large-scale spear-phishing campaign using RDP files](https://pn394.keap-link014.com/v2/click/14a41e2b6c76f906ccf67dcc255a288c/eJyNkE1rwzAMhv-Lz3WdON2guZVSSmjXw9jOw7XVRMyxja2spKX_fc42etpgF4H0vnr0cWUETjlqDKtZcNVywWYsgsaA4GjtHSn9JVYLuZQzZtG9b6MfAquvv7Xe9alalg_yccZoDJAtL8-r9a45bN_2zWGXrUHFPOI_nKqQZSnvoM3Tqtmz2-1PMvRIm48MT6ymOMB0kcF8Fb1Gm_0dUUi1EOfzed6jjj75E8217wU4PiSRQA8RaRRH61shC7kQZSHkUvRoHLYd8aPFy0VFw7V3ZtCUuFWxBZ60sjkGUJGHDlOHruVa9UFhO6GnNJrAT2ghibyqCgGc-fnzDsbvhW-fVUKIAA==)
- AWS Security: [Amazon identified internet domains abused by APT29](https://pn394.keap-link014.com/v2/click/3081f214b841cbe670f7f3d9b9889995/eJyNkEFPwzAMhf9Lzs1C002ivU3TNFUdOyA4o7TxwKJ1osQdKlP_OxlDO4HE1e_5e34-CwYyxLUVlfBUlEuRiQAdegTijSM23bdYLHWpM9Ejve-CG72ozr-t3vTLNM9X-j4TPHlIlqfH9aapD7uXfX1oktWbkCL-wynudJ7rG2j7sK73Yp7_JMOAvD0leBQVhxEujSymVvwc-uR_Y_axUsp8xIUZzKejRecG1fbuNaoI3RiQJ3VVJNoEwiOClUgMgYCldYNBitK0Y0zzdpLGsy5VyjbeA9mfxzUwXS-YvwBTGXet)
- The Centre for Cybersecurity Belgium: [Warning: Government-themed Phishing with RDP Attachments](https://pn394.keap-link014.com/v2/click/78d63a4db98fcc327aea5a16b27d3599/eJyNkEFvwjAMhf-Lzw2lLTvQG0IIVWUcpu08BeKRCOpYiaFCqP99KUOcNmknS36fn599A0HSJI2BGpiq-QwyCLh37JBk6Un0_i5Ws3JeZnBydFwHf2aob7-NPvWxWxQv1TQDuTIm5P1tsWyb7fpz02zbhLIOacV_fKppWRTl02j1umg2MAx_OmPnZHVJ5hFqCWccLzIuXSUf4ZR4K8KxznMtvQ_HSdRf6KnH3WSHeaLSoCLsoxLHUWkyqteBHB3yR1UHf8FA3QiKxQ6NYuuiHaVgWGlJX7PdPUAGmhnJPF7Z4vUn0_ANJHt_cA==)
- Computer Emergency Response Team of Ukraine: [RDP configuration files as a means of obtaining remote access to a computer or "Rogue RDP"](https://pn394.keap-link014.com/v2/click/368f1bb8aebe8e33c77582feccb3e930/eJyNkE8LgkAQxb_LnCVdNau9RUQsmoeocyw61JKtyzoKIn73tj_UpaDrvPd-w3sDEGqpSZTAwehoEYMHFgtlFGpa1Zpk8RCjOFyEHlRKXza2bg3w4Vv0rd-vjE0jl6HeoLPsd8tVKvLNMRN56qxGWvfiH04UhIx9QOvtUmQwjj_JeFW07hy8AU62xXujUrlWdLCV85-JTMN9v0BLk1PdTVrpS0uqqNBPwjkLZomjSGNQl68JUuyfrPEG1Vdh0Q==)

If you have any questions or need assistance, please do not hesitate to [reach out to our team!](https://www.attitudeit.ca/contact)

![](https://www.attitudeit.ca/hs-fs/hubfs/Attitude%20IT%20favicon%20dark%20background%20(250%20%C3%97%20250%20px)-1.png?width=116&height=116&name=Attitude%20IT%20favicon%20dark%20background%20(250%20%C3%97%20250%20px)-1.png)

## Attitude IT

Since 2003, Attitude IT has been helping businesses in Ontario keep their technology on course.

## Ready to Transform your Business with Little Effort Using Brightlane?

[Register Now](https://www.example.com)

You May Like These

## Related Articles

![](https://www.attitudeit.ca/hs-fs/hubfs/AI-Generated%20Media/Images/cybersecurity.jpeg?width=700&name=cybersecurity.jpeg)

### [Cybersecurity Principles for Everyday Use](https://www.attitudeit.ca/the-attitude-it-today/cybersecurity-principles-for-everyday-use)

![](https://www.attitudeit.ca/hs-fs/hubfs/money%20hook.png?width=700&name=money%20hook.png)

### [How $43,000 Got Stolen From A Small Business In The Blink Of An Eye](https://www.attitudeit.ca/the-attitude-it-today/how-43000-got-stolen-from-a-small-business-in-the-blink-of-an-eye)

![](https://www.attitudeit.ca/hs-fs/hubfs/OIP-1.jpg?width=700&name=OIP-1.jpg)

### [“Your Reservation Has Been Updated” – Don’t Fall For This Travel Scam](https://www.attitudeit.ca/the-attitude-it-today/your-reservation-has-been-updated-dont-fall-for-this-travel-scam)

---

[![Attitude IT on course white (1100 × 250 px) (1)](https://www.attitudeit.ca/hs-fs/hubfs/Attitude%20IT%20on%20course%20white%20(1100%20%C3%97%20250%20px)%20(1).png?width=1100&height=250&name=Attitude%20IT%20on%20course%20white%20(1100%20%C3%97%20250%20px)%20(1).png "Attitude IT on course white (1100 × 250 px) (1)")](https://attitudeit.ca)

<https://www.attitudeit.ca/the-attitude-it-today> <https://www.linkedin.com/company/attitude-computers/> <https://www.facebook.com/AttitudeComputers> <https://www.instagram.com/ontarioattitudeit/>

- [Home](https://www.attitudeit.ca)
- [About Us](https://www.attitudeit.ca/about-attitude-it)
- [Blog](https://www.attitudeit.ca/the-attitude-it-today)

- [Cybersecurity](https://www.attitudeit.ca/cybersecurity)
- [IT Services](https://www.attitudeit.ca/it-services-attitude-it)

##### [GTA (416) 900-6047](tel:14169006047)

##### [Ajax,Pickering, Whitby (905) 432-7751](tel:19054327751)

##### [Peterborough Port Hope Cobourg Northumberland (613) 480-0652](tel:16134800652)

[Subscribe to Our Newsletter](https://www.attitudeit.ca/the-attitude-it-today#blogsignup)

© 2026 Attitude IT. All rights reserved. [Privacy Policy](https://www.attitudeit.ca/privacy-policy)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Attitude IT",
    "url" : "https://www.attitudeit.ca/the-attitude-it-today/author/attitude-it"
  },
  "dateModified" : "2024-12-10T15:00:02.968Z",
  "datePublished" : "2024-12-10T15:00:00.000Z",
  "headline" : "New Alert From CISA- Beware of Spear-Phishing Emails With Malicious RDP Files",
  "image" : [ "https://www.attitudeit.ca/hubfs/AI-Generated%20Media/Images/phishing%20email.jpeg" ],
  "mainEntityOfPage" : {
    "@id" : "https://www.attitudeit.ca/the-attitude-it-today/new-alert-from-cisa-beware-of-spear-phishing-emails-with-malicious-rdp-files",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://www.attitudeit.ca/hubfs/Attitude%20IT%20on%20course%20(1100%20%C3%97%20250%20px).svg"
    },
    "name" : "Attitude IT"
  }
}
```