Python Delivering AnyDesk Client as RAT, (Tue, Dec 17th)
ID: ab3598c8-ad12-56ff-a041-3fc5490eeeea
STIX ID: report--ab3598c8-ad12-56ff-a041-3fc5490eeeea
Feed Name: SANS ISC Diary
Threat Score
The report describes a Python script that silently installs and reconfigures AnyDesk on Windows and Linux to enable unattended remote access (by adding or overwriting ad.anynet.* settings), restarts the service, and exfiltrates victim details to a C2 at 95.164.17.24:1224. The sample (an5.py) has a low VT detection and demonstrates a practical RAT deployment technique using legitimate remote-administration software.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
