icon

Digital safety starts here for both commercial and personal Use...

Defend Your Business Against the Latest WNY Cyber Threats We offer Safe, Secure and Affordable Solutions for your Business and Personal Networks and Devices.



WNYCyber is there to help you to choose the best service providers in Western New York... We DO NOT provide the services ourselves, as we are Internet Programmers who have to deak daily with Cyber Threats... (Ugghhh)... So we know what it's like and what it takes to protect OUR and OUR CUSTOMERS DATA... We built this Website to help steer you to those that can give you the best service at realistic and non-inflated prices. We do charge or collect any fees.

CERT-UA Warns of Cyber Scams Using Fake AnyDesk Requests for Fraudulent Security Audits

Summary:
The Ukrainian government's Computer Emergency Response Team (CERT-UA) has received several reports of unidentified actors falsely claiming to represent CERT-UA in an attempt to connect to victims’ systems via AnyDesk. These individuals impersonate CERT-UA, using its logo and the AnyDesk ID "1518341498" (which may change), and send requests to connect victims’ AnyDesk under the guise of a "security audit” to check the level of security. While CERT-UA may use remote access software, including AnyDesk, to assist cyber-protected facilities in addressing cyber incidents, the agency notes that such actions occur only after approval through previously agreed channels of interaction.

Security Officer Comments:
These types of attacks are only effective if the AnyDesk software is running on the targeted system and the actor has access to the victim’s AnyDesk ID. In this case, these IDs are likely compromised via means of social engineering or obtained via other computers from which remote access was once authorized. By remoting into the victim’s system via AnyDesk, this could enable the actors to steal other data of interest or even deploy malicious payloads for further persistence.


Suggested Corrections:
Recommendations from CERT-UA:
  1. Any remote access software should be enabled only for the duration of the session in which it is used.
  2. The fact of carrying out work that involves remote access must be personally agreed upon using existing communication channels.
  3. In case of detection of such anomalies, immediately inform the cyber defense units and, if necessary, CERT-UA in order to promptly take response measures.
Link(s):
https://thehackernews.com/2025/01/cert-ua-warns-of-cyber-scams-using-fake.html
https://cert.gov.ua/article/6282069