NLBrute is a Windows password brute-force utility used by intruders to attack exposed Remote Desktop Protocol services and gain or expand access within victim environments. It is not a self-propagating malware family in the classic sense, but an operator-driven offensive tool commonly found in ransomware and post-compromise intrusion toolsets. Reported use shows it being configured with username and password lists to systematically attempt logins against systems with Remote Desktop enabled.
NLBrute has been observed in human-operated ransomware operations, including activity associated with the PARINACOTA intrusion set and in tooling recovered from Netwalker-related campaigns. In these contexts it supported brute-force attacks against internet-facing RDP services as part of rapid monetization or broader enterprise compromise. It has also been reported in later-stage intrusion activity alongside credential-dumping tools, privilege-escalation exploits, and Remote Desktop access to move through networks.
The tool’s primary role is credential guessing against Windows hosts reachable over RDP. Successful use can enable initial access when weak external passwords are present, or facilitate lateral movement after attackers obtain internal network reachability. Its operational use is typically paired with reconnaissance, credential theft, privilege escalation, remote administration utilities, and ransomware deployment workflows. Organizations with exposed RDP infrastructure, weak password hygiene, or insufficient access controls are the most relevant targets in observed cases.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct technique documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Tool used by the attackers during post-compromise activity to move through the network.
Password brute-force utility used against RDP for initial access and/or lateral movement within victim networks.
Tool used to brute-force RDP credentials during initial access in PARINACOTA activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.