AnyDesk is a legitimate, dual-use remote desktop application, not inherently malware. It provides interactive screen control, remote administration, file transfer, session recording, and password-protected unattended access. Threat actors abuse these functions to obtain unauthorized access, maintain persistent access, deploy additional payloads, and transfer stolen data. Installing it as a service and configuring unattended access can provide an enduring access channel independent of malware command-and-control infrastructure.
Unauthorized deployments occur through phishing, targeted invoice lures, fraudulent websites, and phone-based social engineering, including impersonation of IT support personnel. AnyDesk is also installed after exploitation of vulnerable public-facing applications, including Apache ActiveMQ through CVE-2023-46604 and Samsung MagicINFO through CVE-2025-4632. Attackers use scripts and remote-management platforms to download and silently install the application, configure an access password, and establish redundant remote-access channels. Its legitimate administrative role can help malicious activity blend into trusted software usage.
Documented abuse spans ransomware operations, financially motivated campaigns, and nation-state intrusions. Users include Medusa, Akira, Qilin affiliates, Magnet Goblin, Scattered Spider subclusters, and STAC4749 operators. The North Korea-aligned DeceptiveDevelopment campaign also uses InvisibleFerret to install and configure AnyDesk on compromised developer systems. Observed deployments include Windows workstations and servers across multiple industries, including aerospace and education. These associations reflect misuse of a commercial product rather than attribution of AnyDesk itself to a particular threat actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In the recently identified attack, the threat actor additionally installed AnyDesk after installing Netcat.
CVE-2025-31161 is a 9.8 CVSS critical severity vulnerability that affects how the CrushFTP file transfer application handles user authentication... CrushFTP versions 10.0.0 through 10.8.3 and 11.0.0 through 11.3.0 are affected by a vulnerability in the S3 authorization header processing that allows authentication bypass.
Hackers exploited Triofox flaw CVE-2025-12480 to bypass auth and install remote access tools via the platform’s antivirus feature.
...Fortinet FortiClient EMS... exploited... The vulnerability in question is CVE-2023-48788... SQL injection...
18 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The group employs compromised RMM tools in their campaigns such as ConnectWise, PDQDeploy, and AnyDesk.
This BAT script downloads and executes AnyDesk and was downloaded from another server, 23.184.48[.]132, which is also associated with ScreenConnect payloads.
In the case of the Apache ActiveMQ vulnerability (CVE-2023-46604), the threat actor installed Netcat and additionally installed AnyDesk.
Trend Micro found ... one Qilin affiliate using Atera to deploy AnyDesk, with ScreenConnect alongside it for redundancy.
Threat Research Team identified a targeted spear-phishing campaign using a fake aerospace-related business invoice delivered via a spoofed domain to deploy malware that silently configures AnyDesk for unattended remote access and persistence.
Threat Research Team identified a targeted spear-phishing campaign using a fake aerospace-related business invoice delivered via a spoofed domain to deploy malware that silently configures AnyDesk for unattended remote access and persistence.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
Once executed, get.js copies several campaign components... The JavaScript then launches g.bat... Systems that do not match these checks follow a PowerShell based execution path... [other systems] execute the 64-bit AS branch through w.py.
Their first attempt used a Windows download utility and their second used PowerShell; Microsoft Defender stopped both.
The actor set DisableRestrictedAdmin to 0 and configured SafeBoot AnyDesk entries and Winlogon automatic logon values.
50 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
58 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Legitimate remote-access software deployed by a Qilin affiliate through Atera, with another remote-access channel maintained for redundancy.
Legitimate remote-management software weaponized in this incident as a rogue remote-access mechanism after compromise.
Legitimate remote-administration software abused by the campaign as an independently installed fallback channel for interactive access after compromise.
Used by the attackers as an alternate remote access channel across the network in incidents that later culminated in ransomware deployment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.