Rpdpatch

Category: backdoor · Aliases: HackTool.RPDPatch, Riskware.RDPPatcher, Tool.RDPWrap, Win32/Patch.RDP · Sample count (EMBER 2018): 1 · Enrichment: insufficient_information · Updated: 2026-07-02T07:23:02Z
Category: BackdoorActor: Unknown / CybercriminalIndustry: Global / OpportunisticMotivation: Opportunistic

Overview

Executive Summary

RPDPatch (or RDP Patcher) is a classification for tools, often flagged as HackTools or Riskware, designed to circumvent Microsoft Windows licensing restrictions. Standard Windows client operating systems (like Windows 10/11 Pro) only allow a single, concurrent Remote Desktop Protocol (RDP) session. RPDPatch alters system DLLs (specifically `termsrv.dll`) to allow multiple, simultaneous RDP connections to a single client machine. While sometimes used legitimately by aggressive IT administrators, threat actors heavily abuse this tool to establish persistent, interactive remote access to compromised systems without interrupting the legitimate user's session.

Infection Vector and Technical Capabilities

RPDPatch is a post-exploitation tool. It is manually deployed and executed by an attacker who has already breached the endpoint, escalated privileges to Administrator or SYSTEM, and wishes to solidify their backdoor access. Upon execution, RPDPatch modifies core OS components:

Threat Assessment

The unauthorized detection of an RPDPatch is a critical indicator of a severe, ongoing compromise. It signifies that an attacker has gained complete administrative control over the endpoint, is actively establishing persistent backdoors, and is likely using the machine as a pivot point to attack the rest of the network via RDP.

Incident Response and Remediation

Known aliases

Threat reports may refer to this family under multiple names:

MITRE ATT&CK Techniques

This family has been observed using the following ATT&CK techniques: T1563.002 T1021.001 T1543.003

Generated Detections (Boilerplate)

These YARA and Sigma rules are auto-generated based on the family name and aliases. They must be heavily tuned before deployment in a production environment.

YARA Rule

rule MALWARE_WIN_RPDPATCH {
    meta:
        description = "Detects Rpdpatch (backdoor)"
        author = "SystemHelpdesk Boilerplate Generator"
        date = "2026-07-06"
    strings:
        $s1 = "rpdpatch" ascii wide nocase
        $s2 = "hacktool.rpdpatch" ascii wide nocase
        $s3 = "riskware.rdppatcher" ascii wide nocase
        $s4 = "tool.rdpwrap" ascii wide nocase
        $s5 = "win32/patch.rdp" ascii wide nocase
    condition:
        uint16(0) == 0x5a4d and any of them
}

Sigma Rule

title: Suspicious Rpdpatch Activity
id: a4162fcfa9db32568c09da2340f8867d
status: experimental
description: Detects generic indicators of the rpdpatch malware family.
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        Image|endswith:
            - '\cmd.exe'
            - '\powershell.exe'
        CommandLine|contains:
            - "*rpdpatch*"
            - "*hacktool.rpdpatch*"
            - "*riskware.rdppatcher*"
            - "*tool.rdpwrap*"
            - "*win32/patch.rdp*"
    condition: selection
level: medium

References & External Analysis

Frequently Asked Questions

How do I remove the Rpdpatch Backdoor from Windows?

Manual removal of Rpdpatch is highly discouraged as it may leave persistence mechanisms intact. We recommend disconnecting the device from the internet and utilizing a professional incident response service or enterprise-grade EDR software to conduct a full forensic sweep.

Is Rpdpatch a virus or a Backdoor?

Rpdpatch is classified as a Backdoor. Unlike traditional viruses that infect files, modern malware like Rpdpatch typically operates as a standalone payload designed to compromise systems, steal data, or deploy secondary stage implants.

What are the main symptoms of a Rpdpatch infection?

Symptoms of Rpdpatch can include unexpected system slowness, unauthorized outbound network traffic to unknown IP addresses, disabled security software, and suspicious background processes running from AppData or Temp directories.

Related Families (Category: backdoor)

Explore other malware families in the same category:

Protect Your Network Against Backdoors

Want to prevent Rpdpatch and similar threats from compromising your organization? Read our comprehensive defensive guide: Backdoor & RAT Protection.

Need help with an active incident? Published by the SystemHelpdesk team.

Machine-readable

Get this profile as JSON: https://jordan123234-malware-families-explorer.static.hf.space/api/rpdpatch.json

Ecosystem & Interactive Environments

This profile is part of the Malware Families Catalog, a public dataset of 2,899 malware families. The catalog is also published across our ecosystem: Hugging Face, Kaggle, Zenodo, Replit, StackBlitz, CodeSandbox, and CodePen.