New Mad Liberator gang uses fake Windows update screen to hide data theft

Share:

A new data extortion group tracked as Mad Liberator is targeting AnyDesk users and runs a fake Microsoft Windows update screen to distract while exfiltrating data from the target device.

The operation emerged in July and although researchers observing the activity did not seen any incidents involving data encryption, the gang notes on their data leak site that they use AES/RSA algorithms to lock files.

Targeting AnyDesk users

In a report from cybersecurity company Sophos, researchers say that a Mad Liberator attack starts with an unsolicited connection to a computer using AnyDesk remote access application, which is popular among IT teams managing corporate environments.

It is unclear how the threat actor selects its targets but one theory, although yet to be proven, is that Mad Liberator tries potential addresses (AnyDesk connection IDs) until someone accepts the connection request.

Once a connection request is approved, the attackers drop on the compromised system a binary named Microsoft Windows Update, which shows a fake Windows Update splash screen.

The only purpose of the ruse is to distract the victim while the threat actor uses AnyDesk’s File Transfer tool to steal data from OneDrive accounts, network shares, and the local storage.

During the fake update screen, the victim’s keyboard is disabled, to prevent disrupting exfiltration process.

In the attacks seen by Sophos, which lasted approximately four hours, Mad Liberator did not perform any data encryption in the post-exfiltration stage.

However, it still dropped ransom notes on the shared network directories to ensure maximum visibility in corporate environments.

Sophos notes that it has not seen Mad Liberator interact with the target prior to the AnyDesk connection request and has logged no phishing attempts supporting the attack.

Regarding Mad Liberator’s extortion process, the threat actors declare on their darknet site that they first contact breached firms offering to “help” them fix their security issues and recover encrypted files if their monetary demands are met.

If the victimized company does not respond in 24 hours, their name is published on the extortion portal and are given seven days to contact the threat actors.

After another five days since the ultimatum has been issued passed without a ransom payment, all stolen files are published on the Mad Liberator website, which currently lists nine victims.

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
1:09 am, Jan 23, 2025
weather icon 2°C
L: 1° | H: 3°
overcast clouds
Humidity: 90 %
Pressure: 1004 mb
Wind: 6 mph SW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 85%
Rain Chance: 0%
Visibility: 7 km
Sunrise: 7:51 am
Sunset: 4:33 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
1° | 3°°C 1 mm 100% 19 mph 89 % 1005 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
5° | 11°°C 1 mm 100% 24 mph 91 % 1003 mb 0 mm/h
Sat Jan 25 9:00 pm
weather icon
2° | 5°°C 0.25 mm 25% 6 mph 93 % 1011 mb 0.26 mm/h
Sun Jan 26 9:00 pm
weather icon
1° | 7°°C 1 mm 100% 15 mph 95 % 1010 mb 0 mm/h
Mon Jan 27 9:00 pm
weather icon
6° | 9°°C 1 mm 100% 27 mph 89 % 993 mb 0 mm/h
Today 3:00 am
weather icon
2° | 3°°C 0 mm 0% 5 mph 89 % 1004 mb 0 mm/h
Today 6:00 am
weather icon
2° | 3°°C 0 mm 0% 7 mph 88 % 1005 mb 0 mm/h
Today 9:00 am
weather icon
4° | 4°°C 0 mm 0% 8 mph 85 % 1004 mb 0 mm/h
Today 12:00 pm
weather icon
8° | 8°°C 1 mm 100% 18 mph 83 % 1000 mb 0 mm/h
Today 3:00 pm
weather icon
7° | 7°°C 1 mm 100% 19 mph 71 % 999 mb 0 mm/h
Today 6:00 pm
weather icon
6° | 6°°C 0.8 mm 80% 15 mph 72 % 1003 mb 0 mm/h
Today 9:00 pm
weather icon
5° | 5°°C 0 mm 0% 10 mph 77 % 1004 mb 0 mm/h
Tomorrow 12:00 am
weather icon
6° | 6°°C 0 mm 0% 12 mph 79 % 1002 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€99,229.34
-2.62%
Ethereum(ETH)
€3,126.02
-2.69%
XRP(XRP)
€3.05
-0.79%
Tether(USDT)
€0.96
-0.04%
Solana(SOL)
€245.35
1.17%
Dogecoin(DOGE)
€0.346307
-2.85%
USDC(USDC)
€0.96
0.00%
Shiba Inu(SHIB)
€0.000019
-3.63%
Pepe(PEPE)
€0.000014
-5.79%
Peanut the Squirrel(PNUT)
€0.349494
-3.98%
Scroll to Top