#anydesk — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #anydesk, aggregated by home.social.
-
ENKI WhiteHat found Kimsuky abusing legitimate tools like Chrome Remote Desktop and AnyDesk for stealthy persistence in phishing campaigns against South Korea and Japan.
#Kimsuky #ChromeRemoteDesktop #AnyDesk #Phishing #NorthKorea
-
Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia
Kimsuky conducted spear phishing campaigns against South Korean and Japanese targets during the first half of 2026, distributing LNK malware through OneDrive share links. The malicious files established scheduled tasks that periodically fetched PowerShell scripts from command-and-control servers to profile systems, exfiltrate Thunderbird and Outlook email data, and log keystrokes. The threat actor installed legitimate remote control software including Chrome Remote Desktop and AnyDesk to evade antivirus detection and maintain multiple access channels. A malicious Chrome extension designed to steal Gmail data exhibited characteristics of AI-generated code, featuring Korean comments, debug strings, and Unicode emoji throughout. The operation employed rotating infrastructure and compromised legitimate Korean servers as command-and-control nodes to impede tracking efforts.
Pulse ID: 6a873495a873c0ec3c6d9880
Pulse Link: https://otx.alienvault.com/pulse/6a873495a873c0ec3c6d9880
Pulse Author: AlienVault
Created: 2026-08-20 17:08:37Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AnyDesk #Asia #Chrome #ChromeExtension #CyberSecurity #EDR #Email #ICS #InfoSec #Japan #Kimsuky #Korea #LNK #Malware #OTX #OpenThreatExchange #Outlook #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #UK #bot #AlienVault
-
Договор поставки ВПО: больше правок не вижу
Специалисты Angara MTDR провели исследование новой фишинговой рассылки хакерской группировки Rare Werewolf (Rezet, Librarian Ghouls) . При открытии вложения на компьютер пользователя устанавливается приложение удалённого управления компьютером AnyDesk в скрытом режиме и утилиты для извлечения паролей из браузеров и почты. Загрузка компонентов атаки осуществляется в несколько этапов, на каждом из которых используются зашифрованные архивы с целью минимизации срабатывания средств защиты.
https://habr.com/ru/companies/angarasecurity/articles/1056230/
#фишинг #впо #anydesk #социальная_инженерия #анализ_вредоносного_по #безопасность_почты #rare_werewolf
-
Ich bekomme einen Scam-Anruf:
"Ihr Konto mit 1,[…] BTC ist gesperrt. Möchten Sie das Geld abheben?"
"Ja!"
"Wann und bei welcher Bank haben Sie investiert?"
"Ähm, weiß ich gar nicht mehr, ähm, bei der #Sparkasse?"
"Wie viel haben Sie investiert?"
"Fünf."
…
[Schweigen]
…
"Haben Sie #AnyDesk auf Ihrem Computer?"🤣 🤣 🤣