HomeSecurityCERT-UA: Attacks via fake login requests on AnyDesk

CERT-UA: Attacks via fake login requests on AnyDesk

The Computer Emergency Response Team of Ukraine (CERT-UA) warns that hackers are trying to impersonate the cybersecurity service by sending fake login requests to AnyDesk.

AnyDesk CERT-UA

AnyDesk's requests claim to be about conducting an audit to assess the "security level."

See also: DoNot Team hackers distribute Android malware as a chat app

" It is important to note that CERT-UA may, under certain circumstances, use remote access software such as AnyDesk ," CERT-UA said . " However, such actions are only taken after prior agreement with the owners of cyber defense objects, through official approved communication channels ."

For the attack mentioned above to be possible, AnyDesk must be installed and running on the target computer. It also requires the attacker to be in possession of the AnyDesk ID (which means they have obtained it earlier through other methods).

See also: Russian Star Blizzard hackers target WhatsApp accounts

To mitigate the risk, programs remote access should only be enabled during their use. In addition, remote access should be allowed after consultation, through official communication channels.

News of the campaign comes as the State Service for Special Communications and Information Protection of Ukraine (SSSCIP) revealed that over 1,042 cyber incidents were detected in 2024.

CERT-UA: Attacks via fake login requests on AnyDesk
CERT-UA: Attacks with fake login requests on AnyDesk

"In 2024, the most active cyber threat groups were UAC-0010, UAC-0050, and UAC-0006, which specialize in cyber espionage, financial data theft, and information-psychological operations," SSSCIP reported.

The UAC-0010 group, also known as Aqua Blizzard and Gamaredon, is said to be behind 277 incidents. UAC-0050 and UAC-0006 have been linked to 99 and 174 incidents, respectively.

See also: Operation 99: Lazarus hackers target Web3 developers

Stay safe!

To protect against threats like those posed by the above groups, organizations must remain vigilant and implement strict security. These can include multi-factor authentication, network monitoring, and regular employee training on safe online practices. Additionally, sharing threat intelligence within the cybersecurity community can enhance preparedness and enable immediate responses to emerging threats. By taking proactive measures and staying informed about the evolving tactics used by cybercriminals, businesses and individuals can mitigate potential risks and protect their data in an increasingly digital world.

Source: thehackernews.com

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS