Original Article Text

Click to Toggle View

AnyDesk says hackers breached its production servers, resets passwords. AnyDesk confirmed today that it suffered a recent cyberattack that allowed hackers to gain access to the company's production systems. BleepingComputer has learned that source code and private code signing keys were stolen during the attack. AnyDesk is a remote access solution that allows users to remotely access computers over a network or the internet. The program is very popular with the enterprise, which use it for remote support or to access colocated servers. The software is also popular among threat actors who use it for persistent access to breached devices and networks. The company reports having 170,000 customers, including 7-Eleven, Comcast, Samsung, MIT, NVIDIA, SIEMENS, and the United Nations. AnyDesk hacked In a statement shared with BleepingComputer, AnyDesk says they first learned of the attack after detecting indications of an incident on their product servers. After conducting a security audit, they determined their systems were compromised and activated a response plan with the help of cybersecurity firm CrowdStrike. AnyDesk says they have revoked security-related certificates and replaced systems as necessary. They also reassured customers that AnyDesk was safe to use and that there was no evidence of end-user devices being affected by the incident. While AnyDesk did not share any on what was stolen during the attack, BleepingComputer has learned that the threat actors accessed source code and code signing certificates. While the company says that no authentication tokens were stolen, out of caution, AnyDesk is revoking all passwords to their web portal and suggests changing the password if it's used on other sites. "AnyDesk is designed in a way which session authentication tokens cannot be stolen. They only exist on the end user's device and are associated with the device fingerprint. These tokens never touch our systems, "AnyDesk told BleepingComputer. "We have no indication of session hijacking as to our knowledge this is not possible." The company has already begun replacing stolen code signing certificates, with Günter Born of BornCity first reporting that they are using a new certificate in AnyDesk version 8.0.8, released on January 29th. The only listed change in the new version is that the company switched to a new code signing certificate and will revoke the old one soon. BleepingComputer looked at previous versions of the software, and the older executables were signed under the name 'philandro Software GmbH' with serial number 0dbf152deaf0b981a8a938d53f769db8. The new version is now signed under 'AnyDesk Software GmbH,' with a serial number of 0a8177fcd8936a91b5e0eddf995b0ba5, as shown below. Certificates are usually not invalidated unless they have been compromised, such as being stolen in attacks or publicly exposed. While AnyDesk had not shared when the breach occurred, Born reported that AnyDesk suffered a four-day outage starting on January 29th, during which the company disabled the ability to log in to the AnyDesk client. "my.anydesk II is currently undergoing maintenance, which is expected to last for the next 48 hours or less," reads the AnyDesk status message page. "You can still access and use your account normally. Logging in to the AnyDesk client will be restored once the maintenance is complete." Yesterday, access was restored, allowing users to log in to their accounts, but AnyDesk did not provide any reason for the maintenance. AnyDesk confirmed to BleepingComputer that this maintenance is related to the cybersecurity incident. It is strongly recommended that all users switch to the new version of the software, as the old code signing certificate will soon be revoked. Furthermore, while AnyDesk says that passwords were not stolen in the attack, the threat actors did gain access to production systems, so it is strongly advised that all AnyDesk users change their passwords. Furthermore, if they use their AnyDesk password at other sites, they should be changed there as well.

Daily Brief Summary

DATA BREACH // AnyDesk Confirms Breach and Urges Password Resets After Hack

AnyDesk production systems were compromised in a cyberattack, allowing hackers to access source code and private code signing keys.

Hack discovered following signs of an incident on AnyDesk's servers; cybersecurity firm CrowdStrike is assisting with the response plan.

Company claims AnyDesk software is still safe and there's no sign of customer device compromise.

Despite no evidence of authentication token theft, AnyDesk resets all web portal passwords and prompts users to change reused passwords.

AnyDesk is issuing new code signing certificates and has released a new software version with a new certificate (version 8.0.8).

The security incident caused a four-day service outage for AnyDesk, preventing logins, now attributed to maintenance related to the breach.

Users are strongly advised to update to the new version of AnyDesk and change their passwords as a precautionary measure.