Suspicious Remote Access Utility - AnyDesk Execution With Known Revoked Signing Certificate (via process_creation)
This rule detects the execution of an AnyDesk binary with a version prior to 8.0.8. Prior to version 8.0.8, the Anydesk application used a signing certificate that got compromised by threat actors. Use this rule to detect instances of older versions of Anydesk using the compromised certificate This is recommended to avoid adversaries abusing the certificate and signing their binaries to bypass detections.
SigmamediumWindowsv1
sigma
suspicious-remote-access-utility-anydesk-execution-with-known-revoked-signing-certificate-via-process-creation
title: Suspicious Remote Access Utility - AnyDesk Execution With Known Revoked Signing Certificate (via process_creation)
id: 77622af4-f1d7-5dde-9375-3d68dc1b96bb
status: stable
description: This rule detects the execution of an AnyDesk binary with a version prior to 8.0.8. Prior to version 8.0.8, the Anydesk application used a signing certificate that got compromised by threat actors. Use this rule to detect instances of older versions of Anydesk using the compromised certificate This is recommended to avoid adversaries abusing the certificate and signing their binaries to bypass detections.
references:
- https://www.bleepingcomputer.com/news/security/anydesk-says-hackers-breached-its-production-servers-reset-passwords/
- https://anydesk.com/en/changelog/windows
author: Huntrule Team
date: 2026-07-17
tags:
- attack.execution
- attack.initial-access
- attack.command-and-control
- attack.t1219
logsource:
product: windows
category: process_creation
detection:
selection_img:
- Image|endswith: '\AnyDesk.exe'
- Description: 'AnyDesk'
- Product: 'AnyDesk'
- Company: 'AnyDesk Software GmbH'
selection_version:
FileVersion|startswith:
- '7.0.'
- '7.1.'
- '8.0.1'
- '8.0.2'
- '8.0.3'
- '8.0.4'
- '8.0.5'
- '8.0.6'
- '8.0.7'
filter_main_uninstall:
CommandLine|contains:
- ' --remove'
- ' --uninstall'
condition: all of selection_* and not 1 of filter_main_*
falsepositives:
- Unknown
level: medium
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.