Technology

New Ransomware Tactics Put Unmanaged Local Admin Accounts Back in the Spotlight

Ransomware isn’t anything new, but the ways in which hackers are exploiting accounts are changing. AI-driven attacks coupled with sophisticated technology have generated new tactics in just the last couple of years.

Phishing schemes and malicious links aren’t going anywhere; however, newer ransomware tactics are focused on speed, aggressive social engineering, and extortion without the need for file encryption.

The compressed timeline means that a user’s accounts or entire device can be compromised in less than an hour  a significant departure from the days-long process back in the early 2000’s.  

 

These new ransomware tactics are threatening the cybersecurity world as a whole. Individuals’ private information is more at risk, and organizations are having to change their security infrastructures to ensure their data remains safe.

One part of the system that remains a critical security risk, particularly because of these advanced tactics, is unmanaged local administrator accounts.

Keep reading to learn more about what constitutes an unmanaged local administrator account, how ransomware tactics are exploiting these accounts, and how to best protect your network.    

What Are Unmanaged Local Administrator Accounts?

To put it simply, unmanaged local administrator accounts are responsible for an individual workstation, as opposed to an entire domain. They are built-in or manually created high-privilege logins on individual devices.

They often fail to use unique passwords, which puts them at risk for cybersecurity attacks.  

A common example is generic local accounts used by a company’s IT support or helpdesk team. These accounts are shared by multiple users and use a common password, which is verbally shared or written down among technical support staff.

Another example is the default built-in local administrative accounts on a Windows workstation. These servers likely have the same factory password across hundreds of machines.    

If you’re unsure if your organization has unmanaged local administrator accounts, you can find them by cross-referencing any account names against corporate directory policies or centralized password managers, such as LAPS.

An endpoint inventory report can also be used to identify any accounts that lack centralized management.

cybersecurity vendor can also help find unmanaged local administrator accounts by leveraging specialized tools for asset discovery and privilege auditing.  

How New Ransomware Tactics Are Exploiting Unmanaged Local Administrator Accounts

Because unmanaged local administrator accounts share the same username and password across multiple devices, they present a security risk known as “pass-the-hash.”

Also known as a lateral movement vulnerability, this means that if an attacker can break into one device, they can access every other device across the shared network via Server Message Block (SMB) or Remote Desktop Protocol (RDP).

Moreover, it’s hard to detect the initial break-in because there is no audit trail from one device to the next.  

Another reason why newer tactics are exploiting these accounts is because of a phenomenon known as “living-off-the-land,” or LOTL. By using legitimate access credentials, bad actors blend in with normal behavior.

This makes it more challenging for security systems to detect actors in the first place, granting them access to the entire network before they corrupt the system entirely.

Once they are inside the system, they can disable any antivirus software, wipe event logs, and delete shadow copies to block recovery mechanisms.

Sophisticated actors can complete these steps relatively quickly, making it nearly impossible for the organization to regain its once-protected data.  

But it’s not only gaining access and breaking down systems quickly that bad actors are interested in. Many are invested in the long-term, meaning they are focused on long-term data exfiltration. 

Unmanaged local administrator accounts are perfect for maintaining silent access because they lack oversight and standard monitoring. With this, bad actors can be granted access to an entire network for an extended period of time. 

Having this type of access can create chaos, as they deploy rogue tasks, modify registry Run keys, or create shadow admin accounts to mimic different types of software.  

How To Best Protect Your Network

New ransomware tactics are becoming more sophisticated by the minute, which is why removing any unmanaged local admin accounts needs to be a priority.

As mentioned, these accounts give hackers easy access to an entire network and can cause both short- and long-term damage.  

Once any unmanaged local admin accounts are identified, you can work to create unique passwords for every local admin.

This can be completed automatically using Microsoft LAPS,  and any remote access can be blocked via Remote Desktop or PowerShell.

Again, a third-party cybersecurity vendor can assist in this process if you or your IT team lacks the time, tools, or internal staff expertise to secure these local accounts. 

Next, be sure to set group policies to stop new local accounts from being created. Educating your staff on the risks of having unmanaged local admin accounts can be beneficial, and it never hurts to over-communicate cybersecurity risks in today’s digital-focused, remote working environment.  

Lastly, continue to watch for any suspicious activity. Just because accounts have been disabled doesn’t mean you’re off the hook from any type of attack.

Turn on security logs to send alerts when a local admin logs in, and continuously audit and monitor administrative access as a preventative measure.   

Setting these protocols in place will safeguard your network, catching unauthorized access early and stopping attackers before they cause detrimental damage.  

Kavichselvan

Kavichselvan is a Cybersecurity Enthusiast and Journalist covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Russian University Leak Exposes GRU Cyber Training Pipeline Behind APT28 and Sandworm

Leaked university records have opened an unusual window into Russia’s military cyber ecosystem. The documents…

52 minutes ago

Dark Caracal Hackers Use Ethereum Blockchain to Keep New Malware Connected After C2 Disruption

Dark Caracal has returned with a new tool that helps attackers stay connected when defenders…

4 hours ago

Claude Code Opus 5 Auto Mode Hijacked via Prompt Injection to Execute Malicious Code

Claude Code Opus 5 in Auto Mode can be tricked into running malicious code via…

5 hours ago

CISA Warns of Linux Kernel Privilege Escalation Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency has added a Linux kernel vulnerability, tracked as…

5 hours ago

Hackers Steal Data of 8.7 Million Customers in Cyberattack on Three UK Airports

Cybercriminals have stolen the personal data of about 8.7 million customers following a cyberattack on…

6 hours ago

100+ Tech and Security Organizations Call for Global Cyber Defense Surge Against AI Attacks

More than 100 technology, cybersecurity, and financial-services organizations have joined OpenAI in an open letter…

8 hours ago