Sophos X-Ops reported that the Mad Liberator ransomware actor used social engineering and the legitimate remote-access tool AnyDesk to gain access to a victim environment, then deployed a fake "Microsoft Windows Update" program to hide data theft activity. The victim accepted an unsolicited AnyDesk connection request believing it was routine IT support, after which the attacker transferred and executed the fake updater, displayed an animated update screen, and disabled keyboard and mouse input through AnyDesk while exfiltrating files from OneDrive and mapped network shares.
During the roughly four-hour intrusion, the attacker also used Advanced IP Scanner for subnet reconnaissance and dropped ransom notes on a shared network location, although Sophos said the group in this case did not establish persistence for the fake update binary. Sophos identified the malware as Troj/FakeUpd-K and said Mad Liberator has primarily emphasized data exfiltration and pressure tactics, with some reports also linking it to encryption and double-extortion activity; the company urged organizations to tighten remote-support procedures, improve user awareness, and restrict AnyDesk connections with access control lists while reviewing AnyDesk logs for suspicious sessions and file transfers.

TTPs, infrastructure, and targeting history in one profile.
1 event from the most recent confirmed update back to the earliest known activity.
Sophos X-Ops reported on a mid-2024 incident involving the Mad Liberator ransomware threat actor. In the observed attack, the actor used an unsolicited AnyDesk session, ran a fake "Microsoft Windows Update" binary to mask activity, conducted reconnaissance, exfiltrated files, and left ransom notes.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.