AnyDesk is a legitimate remote desktop and remote administration application that is frequently abused by threat actors as a dual-use remote access tool rather than malware developed solely for malicious use. In intrusion activity, operators commonly install or silently configure AnyDesk for unattended access to obtain persistent interactive control of compromised systems, maintain backup access channels, and support post-compromise operations. Observed abuse includes direct remote administration, command-and-control facilitation, persistence, lateral movement support, malware deployment, and data exfiltration through built-in file transfer features.
Threat actors have delivered or deployed AnyDesk through multiple intrusion paths. Documented patterns include spearphishing and phishing lures that trick victims into downloading disguised installers, social-engineering campaigns such as recruiter-themed lures and telephone-oriented attack delivery, and post-compromise installation by operators after initial access through other malware or stolen credentials. In several campaigns, other malware families such as BeaverTail and InvisibleFerret downloaded or configured AnyDesk to extend attacker access. AnyDesk has also been used by ransomware and extortion actors including Akira, Trigona, LockBit-linked operators, and by clusters associated with Scattered Spider and MuddyWater operations. It has additionally appeared in activity aligned with Rare Werewolf/Librarian Ghouls and in DPRK-linked developer-targeting campaigns.
On Windows systems, attackers have been observed installing AnyDesk as a service, modifying its configuration to enable unattended access, restarting the application after configuration changes, and using it as a persistent secondary command-and-control channel. In enterprise compromises, operators have used AnyDesk alongside credential theft tools and remote execution utilities to sustain access to servers and workstations. Because it is signed, widely used, and operationally familiar, AnyDesk can blend into legitimate administrative activity and reduce suspicion during hands-on-keyboard intrusions.
Although AnyDesk itself is not inherently malicious, its repeated use across espionage, cybercrime, ransomware, and extortion operations makes it a significant dual-use artifact in incident response. Its presence on systems where it is not approved or expected can indicate unauthorized remote access and ongoing post-exploitation activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2025-31161 is a 9.8 CVSS critical severity vulnerability that affects how the CrushFTP file transfer application handles user authentication... CrushFTP versions 10.0.0 through 10.8.3 and 11.0.0 through 11.3.0 are affected by a vulnerability in the S3 authorization header processing that allows authentication bypass.
Hackers exploited Triofox flaw CVE-2025-12480 to bypass auth and install remote access tools via the platform’s antivirus feature.
...Fortinet FortiClient EMS... exploited... The vulnerability in question is CVE-2023-48788... SQL injection...
15 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Threat Research Team identified a targeted spear-phishing campaign using a fake aerospace-related business invoice delivered via a spoofed domain to deploy malware that silently configures AnyDesk for unattended remote access and persistence.
Threat Research Team identified a targeted spear-phishing campaign using a fake aerospace-related business invoice delivered via a spoofed domain to deploy malware that silently configures AnyDesk for unattended remote access and persistence.
Upon credential submission, victims automatically download an AnyDesk executable disguised as a “runtime diagnostics” tool, granting remote access.
AnyDesk is a popular remote desktop application that allows users to connect to computers and devices remotely... threat actors have been known to utilise AnyDesk's capabilities to control computers, therefore gaining unauthorised access to victims' systems.
AnyDesk is a popular remote desktop application that allows users to connect to computers and devices remotely... threat actors have been known to utilise AnyDesk's capabilities to control computers, therefore gaining unauthorised access to victims' systems.
AnyDesk is a popular remote desktop application that allows users to connect to computers and devices remotely... threat actors have been known to utilise AnyDesk's capabilities to control computers, therefore gaining unauthorised access to victims' systems.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
Upon credential submission, victims automatically download an AnyDesk executable disguised as a “runtime diagnostics” tool, granting remote access.
AnyDesk is the group's preferred remote-access tool for persistence, often abusing deployments already present in the environment.
Upon credential submission, victims automatically download an AnyDesk executable disguised as a “runtime diagnostics” tool, granting remote access.
AnyDesk is the group's preferred remote-access tool for persistence, often abusing deployments already present in the environment.
Использование AnyDesk как финального payload (HTTP_VIP -> AnyDesk) ... Это Ingress Tool Transfer (T1105, C2).
25 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
47 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
AnyDesk was abused as the primary remote access payload, silently configured for unattended access and persistence to provide long-term remote control while minimizing user visibility.
Commercial remote access tool used by Scattered Spider subclusters to gain and persist initial access, often delivered immediately after phishing credential capture to support social engineering narratives.
Legitimate remote access software abused to facilitate attacker access during the intrusion.
AnyDesk is used in the observed Trigona attacks to provide direct remote access on compromised systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.