Remote desktop software maker AnyDesk says it has suffered a cyberattack recently; source: hackers stole source code and private code signing keys
AnyDesk confirmed today that it suffered a recent cyberattack that allowed hackers to gain access to the company's production systems.
BleepingComputerLawrence Abrams
Context & Ripple Effects
This incident sits alongside a recurring security problem for remote-access vendors: TeamViewer had previously added protections after hijack reports, and later disclosed a breach of its corporate environment.
The exposure is especially consequential because the reported theft combines code with signing credentials—the same broad software-trust concern highlighted by the 3CX desktop-app supply-chain compromise.
First-order effects
AnyDesk must treat its software-signing trust chain as exposed, including replacing or revoking affected signing credentials and investigating its production environment.
Customers and IT administrators face an immediate verification problem: they need confidence that AnyDesk software and updates originate from a trusted, remediated release process.
Second-order effects
Remote-access rivals will face renewed pressure to demonstrate separation between corporate systems, production environments, and code-signing infrastructure.
Security teams may tighten controls around remote-support software, while software vendors reassess how source-code access and signing keys are protected and monitored.
Third-order effects
If breaches at remote-access providers continue, the category’s differentiator shifts from convenience toward demonstrable software-supply-chain assurance and incident transparency.
The broader structural risk is that compromise of a trusted vendor can scale beyond its own network; stronger isolation of build and signing systems becomes a baseline expectation rather than a specialist practice.
The trend: Remote-access software is becoming a high-consequence supply-chain trust boundary, making protection of production and signing systems central to vendor credibility.
AnyDesk was hacked and very blurry statements came from the company. No one explained how long the attackers had been inside, what data had been accessed, how long the stolen certificates had been used, and how many customers' systems had been accessed without permission. The...
Just to be clear : this rule is for hunting purposes only. This doesn't imply that the rule causes many false positives - on the contrary. We haven't yet seen files signed with this certificate on VirusTotal. We expect developments regarding AnyDesk's current situation to...
My fears have unfortunately been confirmed, the provider #AnyDesk (remote maintenance software) has been hacked. I have now prepared the confirmation and history in part 1 - part 2 will follow. https://borncity.com/...
All client logins are now available. We will continue to monitor the login functionality to prevent any further interruptions. We appreciate your patience and understanding while we worked towards resolving this issue.
This AnyDesk situation is -=WILD=- When you get a signing cert, it's a bit like Fight Club. The first rule of signing certs is do not get your signing cert stolen. The second rule of signing certs is DO NOT GET YOUR SIGNING CERT STOLEN
Note that ransomware affiliates love using RMM tools like AnyDesk you should already be trying to block them from getting on your boxes and alerting. But I know that can be a big ask. Blocking the category in proxy is the minimum.
A few notes on #AnyDesk: * This shouldn't be coming out on a Friday afternoon when they took systems offline days ago. This is a PR move. Companies that are being transparent don't play these shenanigans * Your code signing cert was stolen? 1/n https://anydesk.com/...
#AnyDesk changed the security certificate for code signing... why? they did this after an unscheduled 48hrs maintenance window.... come on AnyDesk... tell us why :) https://anydesk.com/... [image]
If you hunt for malware abusing the #anydesk certificate keep in mind that malware authors have appended the certificate to their malware all the time (resulting in invalid signatures). These are the files we have in our malware repository. [image]
Spoke w/ AnyDesk on the phone: 1. Confirmed intrusion, but limited impact. IR w/ CrowdStrike & believe TA is out of the network. 2. New code signing certs are on the latest version. 3. No customer data impacted, AnyDesk application is OK, no updates or code tampered with.
So, the rumors were true: AnyDesk has been breached. Announced on Friday afternoon East Coast U.S. time/Friday night in the U.K. Like all responsible vendors looking to keep their customers best informed do.😐
So AnyDesk issued a new code signing cert and urges users to only use the newest version. Version 8.0.7 was alive for like hours or max some days? Why do I have the feeling that the actors placed THEIR version of 8.0.7 at the downloads ...