New Mad Liberator gang uses fake Windows update screen to hide data theft
ID: 677fa601-82c7-57cc-98d1-fe57933d9e9e
STIX ID: report--677fa601-82c7-57cc-98d1-fe57933d9e9e
Feed Name: Bleeping Computer
Threat Score
Mad Liberator is a cyber extortion group targeting AnyDesk users by initiating unsolicited remote sessions, deploying a fake "Microsoft Windows Update" splash (which disables the victim's keyboard) to distract the user while using AnyDesk file transfer to exfiltrate data from OneDrive, network shares, and local storage; observed incidents included ransom notes and publication of stolen files on a leak site, but no file encryption was seen by researchers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
