Saturday, September 5, 2026
Follow on LinkedIn

Top Ten Passwords Used by Hackers to Attack the RDP Servers 

The most common passwords hackers are using in attacks against Remote Desktop Protocol (RDP) services, highlighting critical vulnerabilities in many organizations’ security postures. 

The Specops research team analyzed 15 million passwords used in live attacks against RDP ports, revealing that simple, predictable passwords continue to be exploited by threat actors targeting remote access points.

In an extensive analysis spanning from late 2024 to March 2025, researchers identified the top passwords used in attacks against TCP port 3389, which is commonly used for RDP connections. 

Most Common Passwords in RDP Attacks

The study involved cracking approximately 40% of NTLMv2 hashes collected from honeypot systems specifically designed to monitor these attacks.

The top ten passwords used by attackers were:

  • 123456 (355,088 instances).
  • 1234 (309,812 instances).
  • Password1 (271,381 instances).
  • 12345 (259,222 instances).
  • P@ssw0rd (254,065 instances).
  • password (138,761 instances).
  • Password123 (121,998 instances).
  • Welcome1 (113,820 instances).
  • 12345678 (86,682 instances).
  • Aa123456 (69,058 instances).

The findings reveal a troubling trend: the most frequently used password in these attacks, “123456,” was also identified as the most popular password stolen by malware in the 2025 Breached Password Report. 

This suggests many users continue to rely on simplistic keyboard walks as their primary authentication method.

Password Complexity Analysis

The research team’s analysis of character set complexity showed that nearly half (45%) of passwords used in attacks consisted only of numbers or lowercase letters. 

Only 7.56% of passwords incorporated all four character types (lowercase letters, uppercase letters, numbers, and special characters).

“An end user who had chosen a complex password, even a short basic one, would have been protected against more than 92% of the passwords being used in these RDP port attacks,” noted the research team.

Password Length Vulnerabilities

The study found that 26.14% of passwords used in attacks were exactly 8 characters long, corresponding to the minimum length requirement set by many organizations. 

Alarmingly, only 1.35% of the passwords used in attacks exceeded 12 characters in length.

“If your organization was enforcing passphrases of over 15 characters, your end users would be protected against 98% of the passwords being used in the attack,” the researchers concluded.

Securing RDP Connections

Security experts recommend multiple approaches to protect against these common attack vectors:

  • Implement strong password policies requiring lengthy passphrases with varying character types.
  • Enable multi-factor authentication (MFA) for all RDP connections.
  • Ensure TCP port 3389 uses SSL connections and isn’t directly exposed to the internet.
  • Limit the range of IP addresses authorized to use RDP connections.
  • Keep Windows servers and clients fully patched and updated.

The research coincided with Specops adding over 85 million compromised passwords sourced from honeypot networks and threat intelligence operations to its Breached Password Protection service.

This research demonstrates that despite years of security awareness training, users and organizations continue to implement weak passwords that are easily targeted by hackers.  As remote work remains prevalent, securing RDP connections becomes increasingly critical. 

Organizations must recognize that simple complexity requirements are insufficient; password length combined with robust authentication protocols provides the most effective defense against the ongoing wave of RDP-targeted attacks.

Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup - Try 50 Request for Free

Guru Baran
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Cyber Security Guide

Latest Cyber News

Expert Talks