UNIT.City — місце, де люди працюють... КРАЩЕ! Обирай свій простір просто зараз 👉
Олександр КузьменкоThat's Life
20 January 2025, 15:48
2025-01-20
Cyber experts from CERT-UA warned that attackers are using the name of their unit to access computers through the AnyDesk program
The CERT-UA cyber incident response team (a specialized unit of the State Special Communications Service) reported that unknown attackers on behalf of «CERT.UA» were sending connection requests via the AnyDesk remote support program. They claimed to be conducting a «security audit to check the level of protection.»
The CERT-UA cyber incident response team (a specialized unit of the State Special Communications Service) reported that unknown attackers on behalf of «CERT.UA» were sending connection requests via the AnyDesk remote support program. They claimed to be conducting a «security audit to check the level of protection.»
«It is important to emphasize that CERT-UA, under certain circumstances, can indeed use software tools for remote access, including AnyDesk. However, such actions are performed only after prior agreement with the owners of cyber defense facilities through officially approved communication channels,» cyber experts at the State Service for Special Communications reported.
According to them, this activity does not belong to the activities of CERT-UA and is «another attempt by attackers to apply social engineering methods, in particular, manipulation of trust and use of authority.»
CERT-UA explained that such an attack can only be carried out if the attackers have the victim’s AnyDesk ID and the AnyDesk program installed and active on the computer.
«This may indicate previous compromised access to AnyDesk credentials, for example, through other computers previously used for authorized remote access,» cyber experts believe.
They gave some tips on how to avoid this type of threat:
enabling remote access programs, such as AnyDesk, should be done exclusively for the duration of their use session;
remote access work must be coordinated in person through existing official communication channels;
If suspicious activity or anomalies are detected, immediately notify cyber security units and, if necessary, CERT-UA for rapid response.