A cyberattack on the servers of state organizations in Uzbekistan has been detected.
UzCERT reported that data in some systems was encrypted as a result of attacks and urged organizations to immediately strengthen cybersecurity measures.

Massive cyberattacks targeting unauthorized access via the RDP service to computers and servers of state organizations and economic entities in Uzbekistan have been detected. The UzCERT service of the Cybersecurity Center reported this.
During investigations conducted by UzCERT, a number of foreign IP addresses belonging to the malicious C2 (Command and Control) infrastructure used to manage the cyberattacks were identified.
According to preliminary analyses, the information systems of some organizations were compromised as a result of the attacks. In particular, it was found that data on some servers and computers had been encrypted. Currently, investigation and analysis work on the incidents is ongoing.
UzCERT called on employees responsible for cybersecurity in organizations to temporarily disable the RDP service if not necessary, or to restrict direct access via the internet.
It was also recommended to allow access to RDP only through trusted IP addresses or VPN, enable the Network Level Authentication (NLA) function, and not leave port 3389 open to the internet.
Administrators and users with RDP access rights were requested to change their passwords to complex ones, implement multi-factor authentication (MFA), and monitor network activity in an enhanced manner through tools such as firewalls, IDS/IPS, SIEM, and EDR/XDR.
If signs of compromise are detected, it is necessary to immediately disconnect the information system from the network, prevent the spread of the incident, and preserve the necessary evidence.
UzCERT requested that the service be immediately notified in the established manner about any detected cyber incident or signs of system compromise.








