← Back to Feed

Attacker enables RDP, creates admin, erases evidence in ten seconds

June 22, 2026 · Heimdal Security · Severity: CRITICAL

At 06:34am on 2 June 2026, an attacker logged on to a customer’s network. In a single automated burst, they switched on remote desktop and created a rogue administrator account. And deleted the evidence behind them.  The intrusion reached 34 endpoints and was over in under ten seconds.  Heimdal Extended Threat Protection (XTP) and Ransomware […] The post Attacker enables RDP, creates admin, erases evidence in ten seconds appeared first on Heimdal Security Blog.

Key Takeaways

  • An attacker automated a full intrusion enabling RDP, creating an admin account, and deleting evidence in under ten seconds.
  • The intrusion reached 34 endpoints and was over in under ten seconds.
  • Heimdal Security documented the rapid automated attack on a customer's network.
☕ Buy a Coffee