Case of Ransomware Infection in a Company Using Local Administrator Accounts Set with Same Password

Case of Ransomware Infection in a Company Using Local Administrator Accounts Set with Same Password

After analyzing the infected systems of the company that suffered damage from the recent Lockis ransomware infection, the ASEC analysis team discovered that the attacker executed the ransomware after RDP accessing the infected systems with local Administrator accounts.  An investigation of local Administrator information of the infected systems showed that