← Back to Feed
Attacker enables RDP, creates admin, erases evidence in ten seconds
June 22, 2026 · Heimdal Security · Severity: CRITICAL
At 06:34am on 2 June 2026, an attacker logged on to a customer’s network. In a single automated burst, they switched on remote desktop and created a rogue administrator account. And deleted the evidence behind them. The intrusion reached 34 endpoints and was over in under ten seconds. Heimdal Extended Threat Protection (XTP) and Ransomware […] The post Attacker enables RDP, creates admin, erases evidence in ten seconds appeared first on Heimdal Security Blog.
Key Takeaways
- An attacker automated a full intrusion enabling RDP, creating an admin account, and deleting evidence in under ten seconds.
- The intrusion reached 34 endpoints and was over in under ten seconds.
- Heimdal Security documented the rapid automated attack on a customer's network.