logo

New Mad Liberator gang uses fake Windows update screen to hide data theft

ID: 677fa601-82c7-57cc-98d1-fe57933d9e9e

STIX ID: report--677fa601-82c7-57cc-98d1-fe57933d9e9e

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-08-17

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Mad Liberator is a cyber extortion group targeting AnyDesk users by initiating unsolicited remote sessions, deploying a fake "Microsoft Windows Update" splash (which disables the victim's keyboard) to distract the user while using AnyDesk file transfer to exfiltrate data from OneDrive, network shares, and local storage; observed incidents included ransom notes and publication of stolen files on a leak site, but no file encryption was seen by researchers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.