By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: CERT-UA Warns of Cyber Scams Using Fake AnyDesk Requests for Fraudulent Security Audits
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > CERT-UA Warns of Cyber Scams Using Fake AnyDesk Requests for Fraudulent Security Audits
Tech News

CERT-UA Warns of Cyber Scams Using Fake AnyDesk Requests for Fraudulent Security Audits

By Viral Trending Content 4 Min Read
Share
SHARE

Jan 21, 2025Ravie LakshmananMalware / Cyber Threat

Fake AnyDesk

The Computer Emergency Response Team of Ukraine (CERT-UA) is warning of ongoing attempts by unknown threat actors to impersonate the cybersecurity agency by sending AnyDesk connection requests.

The AnyDesk requests claim to be for conducting an audit to assess the “level of security,” CERT-UA added, cautioning organizations to be on the lookout for such social engineering attempts that seek to exploit user trust.

“It is important to note that CERT-UA may, under certain circumstances, use remote access software such as AnyDesk,” CERT-UA said. “However, such actions are taken only after prior agreement with the owners of objects of cyber defense through officially approved communication channels.”

However, for this attack to succeed, it’s necessary that the AnyDesk remote access software is installed and operational on the target’s computer. It also requires the attacker to be in possession of the target’s AnyDesk identifier, suggesting that they may have to first obtain the identifier through other methods.

Cybersecurity

To mitigate the risk posed by these attacks, it’s essential that remote access programs are enabled only for the duration of their use and the remote access is coordinated through official communication channels.

News of the campaign comes as Ukraine’s State Service for Special Communications and Information Protection (SSSCIP) revealed that the cyber agency’s incident response center detected over 1,042 incidents in 2024, with malicious code and intrusion efforts accounting for more than 75% of all the events.

“In 2024, the most active cyber threat clusters were UAC-0010, UAC-0050, and UAC-0006, specializing in cyber espionage, financial theft, and information-psychological operations,” the SSSCIP said.

UAC-0010, also known as Aqua Blizzard and Gamaredon, is estimated to be behind 277 incidents. UAC-0050 and UAC-0006 have been found to be linked to 99 and 174 incidents, respectively.

The development also follows the discovery of 24 previously unreported .shop top-level domains likely associated with the pro-Russian hacking group known as GhostWriter (aka TA445, UAC-0057, and UNC1151) by connecting disparate campaigns targeting Ukraine last year.

An analysis undertaken by security researcher Will Thomas (@BushidoToken) found that the domains used in these campaigns used the same generic top-level domain (gTLD), the PublicDomainsRegistry registrar, and Cloudflare name servers. All the identified servers also have a robots.txt directory configured.

As the Russo-Ukrainian war approaches the end of its third year, cyber-attacks have also been recorded against Russia with an aim to steal sensitive data and disrupt business operations by deploying ransomware.

Cybersecurity

Last week, cybersecurity company F.A.C.C.T. attributed the Sticky Werewolf actor to a spear-phishing campaign directed against Russian research and production enterprises to deliver a remote access trojan known as Ozone that’s capable of granting remote access to infected Windows systems.

It also described Sticky Werewolf as a pro-Ukrainian cyberspy group that mainly singles out state institutions, research institutes, and industrial enterprises in Russia. However, a previous analysis from Israeli cybersecurity company Morphisec pointed out that this connection “remains uncertain.”

It’s not known how successful these attacks were. Some of the other threat activity clusters that have been observed targeting Russian entities in recent months include Core Werewolf, Venture Wolf, and Paper Werewolf (aka GOFFEE), the last of which has leveraged a malicious IIS module called Owowa to facilitate credential theft.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

Meta Pauses Work With Mercor After Data Breach Puts AI Industry Secrets at Risk

What impact might Medtronic’s new lab have on Galway’s medtech ecosystem?

Casio’s AI Pet Moflin Review

iPhone 18 Pro Max Leaks: Smaller Dynamic Island and More

Irish Government approves ‘next-generation sites’ for industry

TAGGED: CERT-UA, Cyber Security, Cyber Threat, Cybersecurity, Incident response, Internet, Malware, social engineering, Spear-Phishing
Share This Article
Facebook Twitter Copy Link
Previous Article 533 (not a new and innovative formation)
Next Article Honor Magic 7 Pro Camera Review: The Ultimate Camera Phone?
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Romanian foreign minister in Kyiv on Bucha anniversary to witness ‘moment of resilience’
World News
Ethereum Foundation Just Changed Its Playbook. The Signal Is Hard to Ignore
Crypto
Dying Light: The Beast Restored Land Hotfix Makes Kyle Less Hangry, Addresses Multiple Issues
Gaming News
Meta Pauses Work With Mercor After Data Breach Puts AI Industry Secrets at Risk
Tech News
Liverpool among frontrunners to sign the next Alexander Isak for £100m
Sports
Food inflation to continue if West Asia war goes on: UN
Business
Cambodian lawmakers propose severe prison time for crypto scammers
Crypto

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Investing £5 a day could help me build a second income of £329 a month!

Brussels unveils plans for a European Degree but struggles to explain why

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
Trump evokes more anger and fear from Democrats than Biden does from Republicans, AP-NORC poll shows
March 28, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?