AnyDesk may have been owned.
They just had a several day authentication outage they describe as “planned maintenance” (it wasn’t planned) and have now reemerged with a new client, with this in the update notes:
AnyDesk may have been owned.
They just had a several day authentication outage they describe as “planned maintenance” (it wasn’t planned) and have now reemerged with a new client, with this in the update notes:
Waiting for the Friday 11pm blog dump announcing cyber incident
@GossiTheDog Malware signed by their key: https://www.virustotal.com/gui/file/ac71f9ab4ccb920a493508b0e0577b31fe547aa07e914f58f1def47d08ebcf7d/behavior
@GossiTheDog 🤦♂️ Well, that'll teach me, sorry
If anybody wants a VirusTotal search for _valid_ signed AnyDesk binaries:
signature:"philandro Software GmbH" signature:9CD1DDB78ED05282353B20CDFE8FA0A4FB6C1ECE entity:file tag:signed NOT tag:invalid-signature
I don't see any which are triggering suspect AV or behavioural triggers, going back to beginning of January.
There we go, 10pm on the dot UK time on Friday.... again.
AnyDesk breached, Crowdstrike in doing IR.
@GossiTheDog Again? Are they getting targeted every Friday?
@GossiTheDog LOL, production thoroughly owned, code signing certificate presumed stolen, TLS certificates presumed stolen, login portal passwords presumed stolen, but "the situation is under control and it is safe to use AnyDesk."
Riiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiight.
If you see stories about lots of AnyDesk creds being leaked - it’s completely unrelated this incident. They’re from info stealers and have existed for years. #threatintel
GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.
All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.