Remote desktop software maker AnyDesk disclosed that it suffered a cyber-attack that allowed hackers to gain access to the company’s production systems.
AnyDesk is a remote access solution that allows users to remotely access computers over a network or the internet. The program is very popular with the enterprise, which use it for remote support.
The incident which was discovered following a security audit is not a ransomware attack and the company has notified relevant authorities.
The German company stated that they have revoked all security-related certificates and systems have been remediated or replaced where necessary. They will also be revoking the previous code signing certificate for the binaries shortly and have already started replacing it with a new one.
As a precaution, AnyDesk has also revoked all passwords to its web portal, my.anydesk[.]com, and is urging users to change their passwords if the same passwords have been reused on other online services.
It is also recommending that users download the latest version of the software, which comes with a new code signing certificate.
AnyDesk did not disclose when and how its production systems were breached. It’s currently not known if any information was stolen following the hack. However, it emphasized there is no evidence that any end-user systems have been affected.
AnyDesk has over 170,000 customers, including Amedes, AutoForm Engineering, LG Electronics, Samsung Electronics, Spidercam, and Thales.
However, in a recent update, cybersecurity firm Resecurity said it found two threat actors, one of whom goes by the online alias “Jobaaaaa,” advertising a considerable amount of login data for AnyDesk customer accounts for sale at Exploit[.]in.
The threat actor has been found offering 18,317 accounts for $15,000 in cryptocurrency.
Notably, the timestamps visible on the shared screenshots by the actor illustrate successful unauthorized access dated February 3, 2024 (post-incident disclosure). It is possible that not all customers have changed their access credentials, or this mechanism was still ongoing by the affected parties.
Currently it is not sure whether the data are from the AnyDesk hack, or collected from compromised user systems or derived from other sources and compiled for the sale.














Comments