Malware
Egregor
According to Heimdal, Egregor ransomware infection happens via a loader, then, in the victim’s firewall, it enables the Remote Desktop Protocol.
Egregor is a Windows malware family.
Background
Per Heimdal, an Egregor ransomware infection begins with a loader, after which the malware turns on the Remote Desktop Protocol in the victim's firewall. From there it can move laterally through the network, locating and shutting down any antivirus software it encounters. It then encrypts the data and drops a ransom note called "RECOVER-FILES.txt" into every affected folder.
Source: Malpedia (Fraunhofer FKIE).