logo

Threat Alert: The Anydesk Breach Aftermath

ID: 1dd6829a-120a-50f6-a7aa-33dded8e649d

STIX ID: report--1dd6829a-120a-50f6-a7aa-33dded8e649d

Feed Name: Cybereason Blog

Threat Score
70/100

Date Published: 2024-03-22

Date Updated: 2026-04-27

Author: Cybereason Security Services Team

...
...

Cybereason reports that AnyDesk experienced a production system compromise resulting in the theft of proprietary source code and a private code-signing certificate; attackers have used the stolen certificate to sign malware (including Agent Tesla samples) which may be distributed as apparently legitimate AnyDesk binaries. The alert documents observed signed malicious samples, recommends updating AnyDesk to the patched version, rotating AnyDesk portal credentials, and hunting for and remediating signed malicious binaries in customer environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.