threat_intelligence1136 wordsRead on Arc Codex

[Update] Incident affecting AnyDesk solutions (February 5, 2024)

Risks - Confidentiality of data breach - Remote takeover by a malicious actor Affected Systems [Updated February 27, 2024] All software produced by the AnyDesk company (Windows, Linux, MacOS, Android, iOS, AppleTV, On-Premises, etc.) - For Windows, the installable and portable versions that were signed prior to versions 8.0.8 and 7.0.15; - For MacOS, the installable versions that were signed prior to versions 8.0.0; - For "custom" Windows client versions or those used in the "On-premise" solution that were not regenerated in 7.0.14 from the AnyDesk client space; - For "custom" MacOS client versions or those used in the "On-premise" solution that were not regenerated in 7.3.0 from the AnyDesk client space; - For other versions, ANSSI is awaiting further information and invites you to stay tuned for future communications. Summary [Updated February 27, 2024] On January 29, 2024, ANSSI was alerted by BSI that the publisher AnyDesk Software GmbH had suffered a data leak. The source code of the applications developed by the publisher, as well as private certificates and keys may have been stolen. Furthermore, the publisher indicates that two of its relay servers located in Europe were also affected by this incident. The publisher specializes in developing desktop software solutions for remote assistance to users, server administration, remote work, or access to internal company resources not publicly accessible. AnyDesk solutions cover a wide range of operating systems: Linux, Windows, MacOS, Android, iOS, AppleTV, etc. According to the company, the exfiltrated data could potentially be reused in the context of subsequent attacks targeting users of AnyDesk solutions. According to the publisher, these attacks are likely to: - Aim to weaken the security of the communication infrastructure between AnyDesk users, for example through Man-in-the-Middle attacks; - Aim to alter the software published by the company or identified as products of the company. CERT-FR cannot confirm at this stage the likelihood or complexity of implementing such attacks. However, given the nature of this type of software solutions and their terms of use, the compromise of user exchanges or application trapping could serve as an entry point to information systems. Preservation Measures [Updated February 27, 2024] While awaiting further information, CERT-FR recommends implementing the following actions: - Identify and reference on your information systems if one of the AnyDesk solutions is installed (do not forget to check mobile fleets if applicable): - Several methods are proposed in the section "Identify and reference the use of AnyDesk tools on your information systems"; - Once this inventory is completed, sequester the results to facilitate potential future investigations; - Identify whether the installation of this application was made as part of a legitimate, known, and validated activity within your entity; - Identify the sensitivity level of the machines, workstations, servers using these tools, and the business constraints associated with their use; - In the context of risk assessment, identify the impact that an incident scenario involving the potential compromise of one or more of these machines could have; - Based on your risk assessment, and to anticipate potential future doubts, proceed with and sequester a digital investigation report on all affected machines: - If this cannot be done globally, ANSSI recommends starting with the most critical machines; - See the section "Preventive collections"; Based on your risk assessment and business constraints: - For AnyDesk solutions that have not received security updates, consider uninstalling the AnyDesk solution and using an alternative solution; - For Windows and MacOS environments, update the AnyDesk solution (the update must be downloaded from the official publisher website https://anydesk.com); - For other versions, ANSSI is awaiting further information and invites you to stay tuned for future updates published by the publisher; - Once the fleet has been migrated to this new version, and as much as possible, detect/block any application signed with the following certificates: - For Windows fingerprint: 9cd1ddb78ed05282353b20cdfe8fa0a4fb6c1ece serial: 0dbf152deaf0b981a8a938d53f769db8 Valid from: Monday, December 13, 2021, 01:00:00 Valid until: Thursday, January 9, 2025, 00:59:59 CN = philandro Software GmbH O = philandro Software GmbH L = Stuttgart S = Baden-Württemberg C = DE - For MacOS fingerprint: 4a1dfb9aa37809b3a123e0ac750bf370469ebaeb serial: 2379881731619607111 (0x210709d364a0d247) Valid from: Tuesday, June 8, 2021, 11:04:30 Valid until: Tuesday, June 9, 2026, 11:04:29 CN = Developer ID Application: philandro Software GmbH (KU6W3B6JMZ) OU = KU6W3B6JMZ O = philandro Software GmbH C = DE - Renew all passwords used for connections to AnyDesk application instances; - Search for any suspicious activity on and originating from these machines starting from 12/20/2023; - If in doubt, contact a qualified incident response provider (PRIS); - Identify and reference the use of AnyDesk tools within the information system: To identify which machines are likely to use the AnyDesk solution, several methods can be combined: At the network level At the network level, identify any machine establishing connections to: *.net.anydesk.com At the system level One of these observables can indicate the presence of AnyDesk. Windows The FastFind tool from ANSSI, attached to this publication, can be used and run on Windows fleets. It includes the following elements which can also be searched via existing tools within IS (e.g., asset inventory tools, EDR, etc.): Presence of one of the following files: - C:\Program Files (x86)\AnyDesk\AnyDesk.exe - %PROGRAMDATA%\Microsoft\Windows\Start Menu\Programs\StartUp\AnyDesk.lnk - C:\Windows\Prefetch\ANYDESK.EXE-[A-F0-9]{8}.pf (Reminder: there is also a portable version of the application) The presence of the following registry keys can also be checked: - HKLM\SYSTEM\ControlSet001\Services\AnyDesk - HKLM\SOFTWARE\Clients\Media\AnyDesk - HKLM\SOFTWARE\Classes\.anydesk\shell\open\command In Windows logs, search for the service creation event 7045 below: ImagePath:"C:\\Program Files (x86)\\AnyDesk\\AnyDesk.exe" –service ServiceName:"AnyDesk Service" ServiceType:"service in user mode", StartType:"Automatic startup" All software signed with the certificate fingerprint: 9cd1ddb78ed05282353b20cdfe8fa0a4fb6c1ece serial: 0dbf152deaf0b981a8a938d53f769db8 Monday, December 13, 2021, 01:00:00 Thursday, January 9, 2025, 00:59:59 CN = philandro Software GmbH O = philandro Software GmbH L = Stuttgart S = Baden-Württemberg C = DE Linux Presence of one of the following files: - /etc/systemd/system/anydesk.service - /usr/bin/anydesk - /usr/lib64/anydesk - /usr/libexec/anydesk - /usr/bin/anydesk - /home/*/.anydesk/ MacOS Presence of one of the following files: - ~/.anydesk/system.conf - ~/.anydesk/service.conf - ~/.anydesk/user.conf - Presence of the application /Applications/Anydesk.app/ Preventive Collections Once the inventory is completed and to facilitate potential future doubts, ANSSI recommends sequestering at least the following items before proceeding with the application version upgrade. Then, in case of suspicion, proceed with their analysis. Logs to collect - System logs of the affected machines; - Application logs of the AnyDesk solutions; - Application-specific logs for a Windows environment: - %APPDATA%\AnyDesk\ad.trace # user interface logs - %PROGRAMDATA%\AnyDesk\ad_svc.trace # service logs - %PROGRAMDATA%\AnyDesk\connection_trace.txt # incoming connection logs - Application-specific logs for a Linux environment: - /home/*/.anydesk/.anydesk.trace - /home/*/.anydesk/anydesk.trace - /root/*/.anydesk/.anydesk.trace - /root/*/.anydesk/anydesk.trace - /var/log/anydesk.trace - /etc/anydesk/connection_trace.txt - Application-specific logs for a MacOS environment: - ~/.anydesk/anydesk.trace - ~/.anydesk/connection_trace.txt - Application-specific logs for a Windows environment: - Network logs related to the affected machines. Documentation - AnyDesk publisher's statement of February 2, 2024 https://anydesk.com/en/public-statement - Best practices in case of intrusion /best-practices-in-case-of-intrusion-on-an-information-system/

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.