AnyDesk confirms attackers breached its production systems
- Organization
- AnyDesk
- Exploit
- Hacking
- Industry
- Software
AnyDesk Software GmbH, the German maker of the widely deployed remote desktop tool of the same name, disclosed on February 2, 2024 that attackers had compromised its production systems. The company said the intrusion was found during a security audit and that it was not ransomware and not an extortion attempt.
AnyDesk said it had revoked all security-related certificates, was revoking and replacing the code signing certificate used for its binaries, and had remediated or replaced systems where necessary. It did not say that the attackers had obtained code signing material. Analysts reading the disclosure inferred that the attackers had got hold of AnyDesk's code signing certificate, which would let them sign arbitrary executables so the files appeared to come from AnyDesk, a route to slipping past security tooling. Infosecurity Magazine reported separately that source code and private code signing keys had been exposed.
As a precaution AnyDesk revoked passwords for its my.anydesk.com web portal and told customers to change those credentials anywhere else they had reused them. On February 4, 2024 Resecurity reported that a threat actor using the handle Jobaaaaa had listed more than 18,000 AnyDesk customer credentials for sale on the Exploit[.]in forum, access Resecurity said would reveal license keys, session details, customer IDs and contact information. SOS Intelligence, Hudson Rock and AnyDesk itself attributed those credentials to infostealer malware on customer machines rather than to this breach. Resecurity disputed that, citing the timing.
The firm engaged CrowdStrike for incident response and notified authorities. It said there was no indication that end user devices had been affected or that tampered versions of its software had been distributed, and stated that the situation was under control and AnyDesk was safe to use.