← Back to Feed

Attacker enables RDP, creates admin, erases evidence in ten seconds

June 22, 2026 · Heimdal Security · Severity: CRITICAL

At 06:34am on 2 June 2026, an attacker logged on to a customer’s network. In a single automated burst, they switched on remote desktop and created a rogue administrator account. And deleted the evidence behind them.  The intrusion reached 34 endpoints and was over in under ten seconds.  Heimdal Extended Threat Protection (XTP) and Ransomware […] The post Attacker enables RDP, creates admin, erases evidence in ten seconds appeared first on Heimdal Security Blog.

Key Takeaways

  • Heimdal Security documented an intrusion where an attacker enabled RDP, created an admin account, and erased evidence in a single automated burst.
  • The attack reached 34 endpoints and was over in under ten seconds, starting at 06:34am on 2 June 2026.
  • Organizations need automated detection that responds faster than attackers, since intrusions can now complete in seconds.
☕ Buy a Coffee