AnyDesk application hacked
In a statement, AnyDesk announced that hackers recently carried out a cyberattack. AnyDesk has warned users regarding security.
12punto
Hackers announced that they hacked many technology companies, primarily Cloudflare and AnyDesk, in the first months of 2024. In a statement, AnyDesk announced that hackers recently carried out a cyberattack. AnyDesk has been hacked! Here are the details…
HUNDREDS OF THOUSANDS OF USERS AFFECTED
AnyDesk, which allows users to access local computers over a network or the internet, recently became the target of malicious users. BleepingComputer confirmed that source code and private code-signing keys were stolen during the attack.
The company is known to have 170,000 customers, including 7-Eleven, Comcast, Samsung, MIT, NVIDIA, SIEMENS, and the United Nations. In a statement shared on Friday afternoon, AnyDesk explained that they first learned of the attack after detecting signs of an incident on their product servers.
After conducting a security audit and determining that their systems had been compromised, the team prepared a response plan with the help of cybersecurity firm CrowdStrike. AnyDesk did not share details regarding whether data was stolen during the attack. However, BleepingComputer learned that threat actors stole the source code and code-signing certificates.
DOES NOT INVOLVE RANSOMWARE
The company also confirmed that the attack did not involve ransomware. Making a statement on the matter, AnyDesk emphasized that they have revoked security-related certificates and have remediated systems as necessary.
Although the company stated that no authentication tokens were stolen, they announced that they have reset all passwords on their website as a precaution. Responding to questions from the press, officials stated, “AnyDesk is designed in such a way that session authentication tokens cannot be stolen. These are only present on the end-user's device and are associated with the device's fingerprint. Therefore, it is possible for us to say that user security is at a high level.”
The company has begun replacing the stolen code-signing certificates. They reported that they used a new certificate in AnyDesk version 8.0.8, which was released on January 29. It should be noted that the only change listed in the new version is the company's transition to a new code-signing certificate and the recent revocation of the old one.