New Mad Liberator gang uses fake Windows update screen to hide data theft

Teilen:

A new data extortion group tracked as Mad Liberator is targeting AnyDesk users and runs a fake Microsoft Windows update screen to distract while exfiltrating data from the target device.

The operation emerged in July and although researchers observing the activity did not seen any incidents involving data encryption, the gang notes on their data leak site that they use AES/RSA algorithms to lock files.

Targeting AnyDesk users

In a report from cybersecurity company Sophos, researchers say that a Mad Liberator attack starts with an unsolicited connection to a computer using AnyDesk remote access application, which is popular among IT teams managing corporate environments.

It is unclear how the threat actor selects its targets but one theory, although yet to be proven, is that Mad Liberator tries potential addresses (AnyDesk connection IDs) until someone accepts the connection request.

Once a connection request is approved, the attackers drop on the compromised system a binary named Microsoft Windows Update, which shows a fake Windows Update splash screen.

The only purpose of the ruse is to distract the victim while the threat actor uses AnyDesk’s File Transfer tool to steal data from OneDrive accounts, network shares, and the local storage.

During the fake update screen, the victim’s keyboard is disabled, to prevent disrupting exfiltration process.

In the attacks seen by Sophos, which lasted approximately four hours, Mad Liberator did not perform any data encryption in the post-exfiltration stage.

However, it still dropped ransom notes on the shared network directories to ensure maximum visibility in corporate environments.

Sophos notes that it has not seen Mad Liberator interact with the target prior to the AnyDesk connection request and has logged no phishing attempts supporting the attack.

Regarding Mad Liberator’s extortion process, the threat actors declare on their darknet site that they first contact breached firms offering to “help” them fix their security issues and recover encrypted files if their monetary demands are met.

If the victimized company does not respond in 24 hours, their name is published on the extortion portal and are given seven days to contact the threat actors.

After another five days since the ultimatum has been issued passed without a ransom payment, all stolen files are published on the Mad Liberator website, which currently lists nine victims.

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
1:05 am, Juli 1, 2025
Wetter-Symbol 23°C
L: 22° | H: 25°
klarer Himmel
Luftfeuchtigkeit: 71 %
Druck: 1014 mb
Wind: 2 mph
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 2%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:47 am
Sonnenuntergang: 9:20 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
22° | 25°°C 0 mm 0% 11 mph 69 % 1015 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
19° | 26°°C 0 mm 0% 12 mph 75 % 1024 mb 0 mm/h
Do. Juli 03 10:00 pm
Wetter-Symbol
14° | 26°°C 0 mm 0% 7 mph 53 % 1029 mb 0 mm/h
Fr. Juli 04 10:00 pm
Wetter-Symbol
16° | 28°°C 0 mm 0% 10 mph 47 % 1028 mb 0 mm/h
Sa. Juli 05 10:00 pm
Wetter-Symbol
16° | 21°°C 1 mm 100% 12 mph 90 % 1019 mb 0 mm/h
Today 4:00 am
Wetter-Symbol
21° | 22°°C 0 mm 0% 3 mph 69 % 1014 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
22° | 23°°C 0 mm 0% 5 mph 64 % 1014 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
28° | 28°°C 0 mm 0% 3 mph 44 % 1014 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
30° | 30°°C 0 mm 0% 6 mph 32 % 1014 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
34° | 34°°C 0 mm 0% 8 mph 26 % 1013 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
32° | 32°°C 0 mm 0% 11 mph 31 % 1013 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
25° | 25°°C 0 mm 0% 8 mph 46 % 1015 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
22° | 22°°C 0 mm 0% 7 mph 61 % 1016 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€91,380.06
-1.10%
Ethereum(ETH)
€2,121.75
-0.58%
Fesseln(USDT)
€0.85
0.01%
XRP(XRP)
€1.91
1.51%
Solana(SOL)
€132.23
1.12%
USDC(USDC)
€0.85
-0.01%
Dogecoin(DOGE)
€0.140900
-2.62%
Shiba Inu(SHIB)
€0.000009
-3.77%
Pepe(PEPE)
€0.000009
-6.36%
Nach oben scrollen