On 2 February 2024, AnyDesk Software GmbH, the German maker of the widely used AnyDesk remote desktop tool, said attackers had compromised its production systems. The company said it had brought in CrowdStrike, revoked "all security-related certificates", would revoke the code signing certificate used for its software, and was revoking every password for its customer web portal, my.anydesk.com, as a precaution. BleepingComputer reported the same day that source code and private code signing keys had been stolen, which AnyDesk did not confirm. AnyDesk has not said how the attackers got in. Reports differ on when the intrusion began: Help Net Security says late December 2023, while The Hacker News cites AnyDesk as placing it in mid-January 2024. AnyDesk said it found no evidence that end-user devices were affected and, later, no evidence of malicious code distributed to customers. The incident matters because a code signing key is the identity a software vendor uses to vouch for its own programs.
Key takeaways
- AnyDesk confirmed on 2 February 2024 that its production systems had been compromised, and said the incident was not ransomware. It did not disclose how the attackers got in.
- The company revoked its security-related certificates and replaced its code signing certificate. BleepingComputer reported that private code signing keys and source code were stolen; AnyDesk did not confirm this.
- AnyDesk reset all my.anydesk.com web portal passwords as a precaution. It said session authentication tokens could not be stolen and that it had no evidence of malicious code reaching customers.
- Akamai advised that versions before 7.0.15 and 8.0.8 were signed with the revoked certificate and that the incident "should be treated as ongoing" because the attackers' intent was unknown.
- The identity lesson: a code signing key is a machine identity trusted by millions of endpoints, so it must be held where a production intrusion cannot reach it, and replaced quickly when that fails.
At a glance
| Organisation | AnyDesk Software GmbH (remote desktop software; more than 170,000 customers, according to the company) |
|---|---|
| When | Intrusion began late December 2023 (Help Net Security) or mid-January 2024 (The Hacker News, citing AnyDesk); service outage from 29 January 2024; disclosed 2 February 2024 |
| Attacker | Unknown. AnyDesk has not attributed the attack and said it was not ransomware |
| Entry point | Not disclosed |
| Identities abused | AnyDesk's code signing certificate and private key (theft reported by BleepingComputer, not confirmed by AnyDesk); other security-related certificates; customer web portal passwords reset as a precaution |
| Impact | Production systems compromised; code signing certificate revoked and replaced; all portal passwords reset; no evidence of affected end-user devices or malicious code distributed, according to AnyDesk |
| Category | NHI. Incident class: confirmed NHI breach (production compromise that forced revocation of the vendor's code signing identity) |
What happened
AnyDesk is remote access software used by IT support teams and managed service providers to connect to computers they look after. In late January 2024 users noticed problems. On 24 January AnyDesk warned of intermittent timeouts on its customer portal, and from 29 January, according to Günter Born as reported by BleepingComputer, it suffered a four-day outage during which client logins were disabled. Its status page called it maintenance. On 29 January it also released version 8.0.8, signed with a new certificate. On 2 February security researcher Kevin Beaumont flagged a possible hack, writing: "They just had a several day authentication outage they describe as 'planned maintenance' (it wasn't planned)".
AnyDesk published its statement that evening. It said it had found indications of an incident on its production servers, confirmed a compromise in a security audit and activated a response plan with CrowdStrike. "We have revoked all security-related certificates and systems have been remediated or replaced where necessary," the company said. "We will be revoking the previous code signing certificate for our binaries shortly." It added: "As a precaution, we are revoking all passwords to our web portal, my.anydesk.com," and "To date, we have no evidence that any end-user devices have been affected." AnyDesk said its systems were designed not to store private keys, security tokens or passwords that could be used to connect to end-user devices.
BleepingComputer went further: "BleepingComputer has learned that source code and private code signing keys were stolen during the attack." It did not name its source, and AnyDesk did not say whether any data was stolen. BleepingComputer noted that older executables were signed as "philandro Software GmbH" and new ones as "AnyDesk Software GmbH". AnyDesk told it: "AnyDesk is designed in a way which session authentication tokens cannot be stolen."
The following day Resecurity reported that a seller was offering 18,317 AnyDesk customer accounts for $15,000 on the Exploit.in forum, The Hacker News reported. AnyDesk said "they appear to be old information obtained from end-user devices infected with malware", and Help Net Security described them as apparently unrelated to the breach. In an update on 8 February, AnyDesk said it had found no malicious changes to its source code and said: "We also have no evidence of malicious code being distributed to customers through any AnyDesk systems."
Timeline
| Date | Event |
|---|---|
| December 2023 | The intrusion begins in late December, according to Help Net Security's 8 February update; The Hacker News cites AnyDesk as placing it in mid-January 2024. |
| 24 January 2024 | AnyDesk warns of intermittent timeouts and degraded service on its customer portal. |
| 29 January 2024 | A multi-day outage begins with client logins disabled; version 8.0.8 is released with a new code signing certificate. |
| 2 February 2024 | Kevin Beaumont flags a possible hack; AnyDesk confirms the production compromise, revokes certificates and resets portal passwords. |
| 3 February 2024 | Resecurity reports 18,317 AnyDesk customer credentials offered for sale; AnyDesk says they appear to come from infostealer infections. |
| 7 February 2024 | Akamai publishes hunting guidance for executables signed with the revoked certificate. |
| 8 February 2024 | AnyDesk says it found no malicious code changes and no evidence of malicious code distributed to customers. |
How it happened: the identity attack path
- Unknown initial access. Attackers reached AnyDesk's production environment by a route the company has not disclosed.
- Presence in production. The compromise was serious enough that AnyDesk revoked all security-related certificates and remediated or replaced systems, with CrowdStrike assisting.
- Signing identity exposed. AnyDesk treated its code signing certificate as no longer trustworthy and replaced it. BleepingComputer reported that the private code signing keys were stolen.
- Customer credentials reset. AnyDesk revoked all web portal passwords as a precaution, while saying its systems do not hold credentials that connect to end-user devices.
- Trust rebuilt on a new key. Customers were told to install releases signed with the new certificate, and defenders were given the old certificate's serial number to hunt for anything else signed with it.
Impact
- Confirmed: AnyDesk's production systems were compromised; all security-related certificates were revoked; the code signing certificate was replaced; every my.anydesk.com password was reset.
- Reported, not confirmed by AnyDesk: theft of source code and private code signing keys, according to BleepingComputer.
- Potential: with a stolen signing key, attackers could sign malware as AnyDesk and evade security tools, Akamai warned. Akamai said it saw AnyDesk in about 25% of the networks it monitors.
- Not found: AnyDesk reported no evidence of affected end-user devices, session hijacking or malicious code distributed to customers. The credentials offered for sale were attributed to infostealer malware, not the breach.
What this means for NHI governance
A code signing certificate and its private key form one of the most powerful machine identities a software company owns. Every computer that runs AnyDesk trusts code because it carries that signature. If the key leaves the company, anyone holding it can make malware look like a genuine AnyDesk release. That is why the response centred on revoking and replacing the certificate, and why customers and security teams then had to hunt for binaries signed with the old one.
The incident also shows what revocation costs when a signing identity has been used for years. Every legitimate older release becomes suspect, and customers must upgrade. Keeping signing keys in hardware security modules or managed signing services, separating them from the production systems that attackers are most likely to reach, and having a tested plan to rotate them limits that damage. Our Machine Identity, PKI and Certificate Lifecycle Guide and Cryptographic Key Management Guide cover these controls.
Recommendations
- Keep code signing keys in hardware or a managed signing service. The private key should never be exportable to build or production servers. See our Cryptographic Key Management Guide.
- Prepare a signing key revocation plan before you need it. Know how you will issue a new certificate, re-sign current releases and tell customers which versions to trust. See our Machine Identity, PKI and Certificate Lifecycle Guide.
- Hunt for binaries signed with a revoked certificate. As Akamai advised, search endpoints for executables carrying the old certificate's serial number and check remote access tools for unexpected behaviour.
- Inventory and govern remote access tools. Find every AnyDesk installation, including unsanctioned ones, and restrict remote access software to approved, current versions. See our Remote Access Identity Guide.
- Reset vendor portal credentials and stop reuse. Change passwords for vendor portals after a supplier breach, enable MFA and check whether the same passwords were used elsewhere. See our Password Security Guide.
- Treat suppliers' signing identities as third-party risk. Ask critical software vendors how they protect and rotate their signing keys. See our Third-Party Access Guide.
Frequently asked questions
What happened in the AnyDesk breach?
On 2 February 2024 AnyDesk said attackers had compromised its production systems. It revoked its security certificates and code signing certificate, reset all web portal passwords and worked with CrowdStrike to remediate. It has not said how the attackers got in.
Was the AnyDesk code signing certificate stolen?
BleepingComputer reported that private code signing keys and source code were stolen. AnyDesk did not confirm this but revoked the certificate and released new versions signed with a replacement. Akamai said versions before 7.0.15 and 8.0.8 were signed with the revoked certificate.
Is AnyDesk safe to use after the breach?
AnyDesk said it had no evidence that end-user devices were affected or that malicious code was distributed through its systems, and advised users to install the latest version signed with the new certificate and change any reused passwords.
Related NHI Mgmt Group resources
GitHub Code Signing Certificate Theft 2022 · MSI Signing Keys Leak 2023 · Storm-0501 Hybrid Cloud Attack 2024 · Machine Identity, PKI and Certificate Lifecycle Guide · Cryptographic Key Management Guide
How NHI Mgmt Group can help
Signing keys and certificates are machine identities that few organisations inventory or rehearse replacing. We help teams find them, protect them and plan their rotation. See our NHI and AI agent security training.
References
- AnyDesk: AnyDesk Incident Response 2-2-2024 (2 February 2024)
- BleepingComputer: AnyDesk says hackers breached its production servers, reset passwords (2 February 2024)
- The Hacker News: AnyDesk Hacked: Popular Remote Desktop Software Mandates Password Reset (3 February 2024)
- Help Net Security: AnyDesk has been hacked, users urged to change passwords (5 February 2024)
- Akamai: The AnyDesk Breach: Overview and Recommendations (7 February 2024)