← Back to Feed
Attacker enables RDP, creates admin, erases evidence in ten seconds
June 22, 2026 · Heimdal Security · Severity: CRITICAL
At 06:34am on 2 June 2026, an attacker logged on to a customer’s network. In a single automated burst, they switched on remote desktop and created a rogue administrator account. And deleted the evidence behind them. The intrusion reached 34 endpoints and was over in under ten seconds. Heimdal Extended Threat Protection (XTP) and Ransomware […] The post Attacker enables RDP, creates admin, erases evidence in ten seconds appeared first on Heimdal Security Blog.
Key Takeaways
- Heimdal Security documented an intrusion where an attacker enabled RDP, created an admin account, and erased evidence in a single automated burst.
- The attack reached 34 endpoints and was over in under ten seconds, starting at 06:34am on 2 June 2026.
- Organizations need automated detection that responds faster than attackers, since intrusions can now complete in seconds.