Threat Advisory: Possible AnyDesk Stolen Code Signing Certificate
ID: 6af90627-9f2a-5a77-a009-8434bb9b444a
STIX ID: report--6af90627-9f2a-5a77-a009-8434bb9b444a
Feed Name: Huntress Blog
The report outlines community concern and rumors that AnyDesk's code-signing certificate may have been compromised after an unexpected maintenance period and a certificate change in AnyDesk 8.0.8; AnyDesk states there is no evidence of user compromise. The write-up highlights the risk that malicious binaries signed with a compromised certificate could evade AV, references a community YARA rule to detect such binaries, and describes Huntress' proactive detection and monitoring efforts for suspicious AnyDesk-signed processes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
