Threat hunts for AnyDesk
4 hunts covering AnyDesk, each with a hypothesis, the queries that test it and what the hunt cannot see.
4 hunts
-
medium Part 2 of 2Research by Cisco Talos
Unauthorized RMM and Ransomware Precursors
An adversary is using unauthorized remote management tools to maintain persistence and is performing credential harvesting or staging ransomware encryption.
3 query1 analytic1 checkpoint1 action2 taskcredential access · discovery · impact -
medium Part 1 of 2Research by Cisco Talos
Cloud Identity and AI Agent Anomalies
An adversary has used social engineering or exploited public-facing remote services to compromise an administrative identity, then used that access to manipulate cloud repositories or orchestration layers via automated agents.
3 query2 analytic2 checkpoint1 action2 taskcredential access · discovery · impact -
high Part 2 of 2Research by Huntress
On-Host Miner Compilation and Resource Hijacking
An adversary has compiled a custom Monero miner directly on an endpoint using .NET and C compilers before executing it as a system process to hijack compute resources.
3 query1 analytic1 checkpoint1 action2 taskdefense evasion · execution · impact -
high Part 2 of 2Research by Huntress
INC Ransomware Wave 2: BYOVD and RAT Deployment
An adversary has deployed remote access tools and Bring Your Own Vulnerable Driver (BYOVD) loaders to neutralize security products before executing INC ransomware.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · defense evasion · execution