New Mad Liberator gang uses fake Windows update screen to hide data theft

Share:

A new data extortion group tracked as Mad Liberator is targeting AnyDesk users and runs a fake Microsoft Windows update screen to distract while exfiltrating data from the target device.

The operation emerged in July and although researchers observing the activity did not seen any incidents involving data encryption, the gang notes on their data leak site that they use AES/RSA algorithms to lock files.

Targeting AnyDesk users

In a report from cybersecurity company Sophos, researchers say that a Mad Liberator attack starts with an unsolicited connection to a computer using AnyDesk remote access application, which is popular among IT teams managing corporate environments.

It is unclear how the threat actor selects its targets but one theory, although yet to be proven, is that Mad Liberator tries potential addresses (AnyDesk connection IDs) until someone accepts the connection request.

Once a connection request is approved, the attackers drop on the compromised system a binary named Microsoft Windows Update, which shows a fake Windows Update splash screen.

The only purpose of the ruse is to distract the victim while the threat actor uses AnyDesk’s File Transfer tool to steal data from OneDrive accounts, network shares, and the local storage.

During the fake update screen, the victim’s keyboard is disabled, to prevent disrupting exfiltration process.

In the attacks seen by Sophos, which lasted approximately four hours, Mad Liberator did not perform any data encryption in the post-exfiltration stage.

However, it still dropped ransom notes on the shared network directories to ensure maximum visibility in corporate environments.

Sophos notes that it has not seen Mad Liberator interact with the target prior to the AnyDesk connection request and has logged no phishing attempts supporting the attack.

Regarding Mad Liberator’s extortion process, the threat actors declare on their darknet site that they first contact breached firms offering to “help” them fix their security issues and recover encrypted files if their monetary demands are met.

If the victimized company does not respond in 24 hours, their name is published on the extortion portal and are given seven days to contact the threat actors.

After another five days since the ultimatum has been issued passed without a ransom payment, all stolen files are published on the Mad Liberator website, which currently lists nine victims.

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
5:44 am, Jul 1, 2025
weather icon 22°C
L: 21° | H: 23°
few clouds
Humidity: 78 %
Pressure: 1014 mb
Wind: 3 mph E
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 20%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:47 am
Sunset: 9:20 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
21° | 23°°C 0 mm 0% 11 mph 78 % 1015 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
19° | 24°°C 0.2 mm 20% 12 mph 76 % 1024 mb 0 mm/h
Thu Jul 03 10:00 pm
weather icon
14° | 26°°C 0 mm 0% 8 mph 52 % 1029 mb 0 mm/h
Fri Jul 04 10:00 pm
weather icon
16° | 29°°C 0 mm 0% 10 mph 48 % 1027 mb 0 mm/h
Sat Jul 05 10:00 pm
weather icon
17° | 22°°C 0.2 mm 20% 13 mph 81 % 1019 mb 0 mm/h
Today 7:00 am
weather icon
22° | 22°°C 0 mm 0% 3 mph 78 % 1014 mb 0 mm/h
Today 10:00 am
weather icon
24° | 27°°C 0 mm 0% 2 mph 69 % 1014 mb 0 mm/h
Today 1:00 pm
weather icon
28° | 31°°C 0 mm 0% 7 mph 46 % 1013 mb 0 mm/h
Today 4:00 pm
weather icon
32° | 32°°C 0 mm 0% 9 mph 25 % 1012 mb 0 mm/h
Today 7:00 pm
weather icon
28° | 28°°C 0 mm 0% 11 mph 31 % 1013 mb 0 mm/h
Today 10:00 pm
weather icon
25° | 25°°C 0 mm 0% 8 mph 48 % 1015 mb 0 mm/h
Tomorrow 1:00 am
weather icon
22° | 22°°C 0 mm 0% 6 mph 65 % 1015 mb 0 mm/h
Tomorrow 4:00 am
weather icon
19° | 19°°C 0 mm 0% 6 mph 76 % 1016 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€90,873.33
-1.25%
Ethereum(ETH)
€2,102.93
-0.96%
Tether(USDT)
€0.85
0.00%
XRP(XRP)
€1.89
1.69%
Solana(SOL)
€129.88
0.93%
USDC(USDC)
€0.85
-0.01%
Dogecoin(DOGE)
€0.139379
-1.98%
Shiba Inu(SHIB)
€0.000009
-1.80%
Pepe(PEPE)
€0.000008
-4.15%
Scroll to Top