Malware researchers from Kaspersky have spotted the TeamXRat gang spreading a new ransomware in Brazil via RDP brute-force attacks. Cybercriminals are using stolen or weak remote desktop credentials to access systems and deliver file-encrypting ransomware. In March experts discovered a ransomware dubbed Surprise that was installed via TeamViewer and executes from memory. In October 2015, experts at BleepingComputer blog reported a strain of ransomware dubbed LowLevel04 that was spreading via Remote Desktop and Terminal Service.”]
Source: http://securityaffairs.co/wordpress/51840/cyber-crime/teamxrat-rdp-ransomware.html

