Exposed RDP: The Open Door Ransomware Gangs Scan For First (2026)

Ulises Paiz

Ulises Paiz, Founder of Ghosxt, has 10+ years in IT infrastructure and cybersecurity, deep DoD infrastructure experience, and 9 certifications including CySA+, Security+, and AZ-104. Before founding Ghosxt, he served as a Senior Solutions Consultant for the DoD and built security programs for 40+ Central Coast businesses. More about Ulises →

We still find it during almost every new-client network review: a firewall rule, sometimes years old, forwarding port 3389 straight to a desktop or server so someone can "just remote in from home." It was set up in an afternoon to solve a real problem, and it has been quietly sitting open ever since. It is also, year after year, one of the most common ways ransomware crews get their first foothold in a small business network.

RDP itself isn't the villain here. Microsoft's Remote Desktop Protocol is a legitimate, useful tool. The problem is what happens when it answers directly on the open internet instead of sitting behind something that controls who can even attempt to log in.

1. Why attackers love a login prompt more than a vulnerability

Most cyberattacks people picture involve some clever exploit: a zero-day, a crafted payload, a bypass of some defense. Exposed RDP doesn't need any of that. It hands an attacker exactly what a legitimate remote employee would use, a login screen, reachable from anywhere. From there it's a matter of guessing or buying the right username and password, not defeating a technical control.

That password doesn't even need to be weak. Credentials leaked in an unrelated data breach, reused across a personal and a work account, or picked up through a completely separate phishing email are enough. Once one working set of credentials lands on that login prompt, the attacker is in as a real, authenticated user, with whatever access that account has, and no antivirus alert fires because nothing "malicious" happened yet. The ransomware deployment, data theft, and lateral movement all come after, once they're already inside.

2. How attackers find it without ever targeting you by name

Nobody has to research your business to find an exposed RDP port. Internet-wide scanning services like Shodan and Censys continuously probe every public IP address and catalog what answers on which port, port 3389 included, and criminal groups either run the same kind of scans themselves or simply buy access to lists that are already built. The moment your firewall starts forwarding that port, it's a matter of time, often not much time, before it shows up in an automated brute-force or credential-stuffing queue running around the clock.

This is the same "smash and grab at internet scale" pattern behind password spray attacks and the internet-facing appliance flaws we've covered in VPN and edge device advisories: attackers aren't picking your business, they're scanning everyone and taking whatever answers. Small businesses aren't skipped for being small; they're an easier, faster win precisely because that RDP port so often has no MFA and a password that hasn't changed in years.

3. What to use instead of a bare RDP port

The fix isn't "never use remote desktop again," it's putting something in front of it that an attacker can't simply log into blind. In order of preference: a modern zero-trust remote access or RMM tool that never opens an inbound port at all is the cleanest option, since there's nothing on the internet to scan for. If your team genuinely needs traditional RDP, put it behind a business VPN with MFA enforced, so a stolen password alone isn't enough, and keep that VPN appliance itself patched and current; VPN and firewall edge devices have their own history of actively exploited vulnerabilities. A properly configured RD Gateway with Network Level Authentication and account lockout policies is the minimum bar if neither of those is available yet.

Whichever route you take, don't stop at RDP. The same review that finds an open 3389 port often turns up other forgotten exposures: an old file server admin panel, a printer's web interface, a test VPN that was never decommissioned. Our attack surface management guide covers how to find everything your network exposes to the internet, not just the one port everyone's heard about.

Where to start this week

Check your firewall's port-forwarding rules for anything pointing to 3389, or to any remote desktop or admin port, today; this one is free and takes minutes, not an afternoon. This week, move whoever's still using bare RDP onto MFA-backed access, and if that account doesn't already have multi-factor authentication turned on, add it as part of the same change. Longer term, this is exactly what a zero-trust approach to remote access is built to prevent: nothing gets in on identity alone, and nothing sits open just because it's convenient.

Ransomware groups still lean on exposed RDP for one simple reason: it keeps working. It's one of the few things on this list that's genuinely free to fix and doesn't require new budget, just an hour with your firewall rules, or a call to whoever manages them.

Frequently asked questions

Why is exposed RDP so dangerous for a small business?

Because it gives an attacker a direct login prompt to a machine on your network from anywhere on the internet, no phishing email required. A guessed or purchased set of working credentials logs them in as a real user. It's remained one of the most common ransomware entry points for years because it skips the need for a more sophisticated exploit entirely.

How do attackers find open RDP ports?

Internet-wide scanning services like Shodan and Censys index every device answering on port 3389, and criminal groups buy access to those results or run their own scans. Once your RDP port is found, it's added to an automated brute-force and credential-stuffing queue running continuously.

Is a VPN enough to make RDP safe?

It's a major improvement, but only if the VPN requires MFA, stays patched, and isn't itself left exposed the way RDP was. Business VPN appliances have their own history of actively exploited vulnerabilities. A VPN with MFA, or a zero-trust remote access tool that never opens an inbound port, is the safer pattern.

How do I know if my business has exposed RDP right now?

An external scan of your public IP addresses will show it, and it's one of the standard checks in an attack surface review or penetration test. If you don't know your business's public IPs or haven't had an external scan run in the past year, that's the gap to close first.

Not sure what's actually exposed on your network?

30 minutes with an engineer with DoD infrastructure experience. We'll scan what your business exposes to the internet, show you plainly what needs to close, and hand you a prioritized fix list. No jargon, no obligation.

Book your free assessment

Prefer to talk first? Email sales@ghosxt.com or call (831) 204-0501.

Book free assessment Call (831) 204-0501