The remote access software provider published a disclosure post to its website late last week describing the incident.
AnyDesk said it activated a remediation and response plan as well as engaged CrowdStrike.
As of Friday, the company had not revoked the previous code-signing certificate for its binaries but said it was in the process of doing so.
As a precaution, AnyDesk said it revoked all passwords to its web portal and recommended users change their passwords if identical credentials are used elsewhere.
According to a blog post from security vendor Resecurity, multiple threat actors have listed more than 18,000 AnyDesk customer credentials to dark web forum Exploit[.
Alexander Culafi is an information security news writer, journalist and podcaster based in Boston.
This Cyber News was published on www.techtarget.com. Publication date: Mon, 05 Feb 2024 21:13:04 +0000