Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
AnyDesk Software

AnyDesk Software Vendor Cyber Rating & Cyber Score

anydesk.com

AnyDesk was founded in Germany in 2014. Its unique remote access software has been downloaded by more than 800 million times by users worldwide. The software is based on the company’s unique proprietary codec, DeskRT, that allows for virtually latency-free collaboration whether you’re down the hall or on the other side of the world. AnyDesk is one of the 50 fastest-growing businesses in Germany and its technology is trusted by millions of people and more than 180,000 customers in 190 countries, including world-renowned Fortune 500 brands.


AnyDesk Software A.I CyberSecurity Scoring

AnyDesk Software
Company Information
Website:http://anydesk.com
Employees number:360
Number of followers:16,906
NAICS:5112
Industry Type:Software Development
Homepage:anydesk.com
AnyDesk Software Risk Score (AI oriented)
Between 600 and 649
logo
AnyDesk SoftwareSoftware Development
Updated:
19/05/2026
646/1000
Poor
Caa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
AnyDesk Software Global Score (TPRM)
xxxx
logo
AnyDesk SoftwareSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

AnyDesk Software
AnyDesk SoftwarePoor
Current Score
646Caa (POOR)
01000
3 incidents
-18 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
648Before Incident
MAY 2026
677Before Incident
Cyber Attack
18 May 2026AnyDesk Software
AnyDesk, Putty, Microsoft and Webex: Microsoft disrupts Fox Tempest malware-signing-as-a-service platform tied to ransomware gangs

Microsoft Disrupts Fox Tempest Malware-Signing-as-a-Service Operation

646After Incident
CRITICAL-31
PUTWEBANYMIC1779215753
Microsoft Disrupts Fox Tempest Malware-Signing-as-a-Service Operation Microsoft has dismantled Fox Tempest, a sophisticated malware-signing-as-a-service (MSaaS) operation that enabled cybercriminals to bypass security defenses by making malicious software appear legitimate. The takedown, revealed in a U.S. District Court filing on Tuesday, targeted a service active since May 2025 that weaponized Microsoft’s Artifact Signing system designed to verify software authenticity to distribute malware and ransomware. Cybercriminals, including affiliates of Rhysida, INC, Qilin, and Akira, used Fox Tempest to obtain fraudulent code-signing certificates, allowing malware to evade detection. The service provided short-lived certificates that mimicked trusted software like AnyDesk, Teams, Putty, and Webex, tricking users and security tools into executing malicious payloads. Microsoft’s investigation found that the group created over 1,000 certificates and established hundreds of Azure tenants to support its operations. The disruption included seizing Fox Tempest’s website, taking down virtual machines, and revoking compromised certificates. Evidence showed cybercriminals complaining about the takedown, with some ransomware affiliates losing access to critical attack tools. Microsoft’s Digital Crimes Unit linked the service to the distribution of malware families such as Oyster, Lumma Stealer, and Vidar, delivered via malicious ads and fake download sites. Fox Tempest operated as a well-resourced criminal enterprise, with dedicated teams for infrastructure, customer support, and financial transactions. Cryptocurrency analysis revealed the group earned millions of dollars from ransomware affiliates, with attacks targeting organizations in the U.S., China, France, and India. Unlike lower-cost cybercrime services, Fox Tempest charged thousands per operation, reflecting the growing sophistication of the cybercriminal ecosystem. The takedown highlights how code-signing abuse undermines trust in digital security, allowing attackers to bypass defenses by masquerading as legitimate software. Microsoft’s actions aim to increase the cost of cybercrime by disrupting critical infrastructure used in large-scale attacks.
INCIDENT DETAILS -
TYPE
Malware-Signing-as-a-Service (MSaaS) Disruption
MOTIVATION
Financial gainCybercrime enablement
IMPACT
Financial Loss: Millions of dollars earned by Fox TempestOperational Impact: Disruption of ransomware and malware distribution operationsBrand Reputation Impact: Undermines trust in digital security and code-signing systems
APRIL 2026
676Before Incident
MARCH 2026
674Before Incident
FEBRUARY 2026
673Before Incident
JANUARY 2026
675Before Incident
Vulnerability
05 Jan 2026AnyDesk Software
LogMeIn, PayPal, CyberProof and AnyDesk: Hackers Use Fake PayPal Notices to Steal Credentials, Deploy RMMs

Phishing-Led Intrusions Abusing Legitimate RMM Tools via Fake PayPal Alerts

670After Incident
LOW-5
GOTPAYCYBANY1768408080
New Phishing Campaign Exploits Fake PayPal Alerts to Hijack RMM Tools A recent surge in phishing attacks is leveraging fake PayPal alerts to compromise both personal and corporate systems through legitimate remote monitoring and management (RMM) tools. CyberProof’s advisory, published on Tuesday, details a shift from seasonal lures such as holiday invites or tax notices to high-urgency financial scams designed to prompt immediate action. Researchers analyzed six incidents across customer environments, including one case where an employee’s personal PayPal account became the initial entry point. On January 5, 2026, CyberProof’s Managed Detection and Response (MDR) team detected suspicious activity that later escalated into corporate access. The attack began with a fraudulent PayPal email, followed by phone-based social engineering. Posing as support staff, the attacker convinced the victim to install LogMeIn Rescue, later switching to AnyDesk to maintain persistence all without triggering endpoint detection and response (EDR) alerts. The attackers employed a tactic of using one RMM tool to install another, a method also observed in recent Broadcom research. This redundancy may help evade detection and exploit trial licenses before they expire. Artifacts from the attacks included multiple LogMeIn Rescue binaries and evidence of active remote sessions. Persistence was achieved through a scheduled task and a disguised startup shortcut, mimicking legitimate system activity. While the immediate goal appears financial, CyberProof warned that such access could be sold to advanced persistent threat (APT) groups, leading to full corporate compromise or ransomware deployment. The firm highlighted the risks of RMM tool abuse and the need for stronger phishing controls, restricted network access to common RMM ports, and the avoidance of exposed remote services like RDP.
INCIDENT DETAILS -
TYPE
Phishing, Social Engineering, RMM Abuse
MOTIVATION
Financial gain, Potential sale of access to APT actors for ransomware deployment
IMPACT
Systems Affected: Corporate and personal devices with RMM tools installedOperational Impact: Potential full corporate compromise, Unauthorized remote accessIdentity Theft Risk: High (if personal accounts were compromised)Payment Information Risk: High (due to PayPal-themed phishing)
DATA BREACH
Personally Identifiable Information: Potential (if personal accounts were compromised)
DECEMBER 2025
675Before Incident
NOVEMBER 2025
675Before Incident
OCTOBER 2025
673Before Incident
SEPTEMBER 2025
672Before Incident
AUGUST 2025
670Before Incident
JULY 2025
668Before Incident
AUGUST 2024
756Before Incident
Ransomware
01 Aug 2024AnyDesk Software
AnyDesk

Mad Liberator Ransomware Group Exploits AnyDesk for Data Exfiltration

645After Incident
CRITICAL-111
ANY000082124
The Mad Liberator ransomware group used social engineering to exploit the remote-access application AnyDesk, gaining unauthorized access and exfiltrating data without the company's knowledge. They carried out a sophisticated attack involving a fake Windows update screen to hide their activities, successfully bypassing the victim's defenses by masking their actions behind a familiar system process. The incident did not involve encryption of data but focused on exfiltrating sensitive information through the misuse of AnyDesk's remote access capabilities. The attackers capitalized on the trust placed in IT departments' regular maintenance practices, which allowed them to carry out the attack unnoticed for almost four hours.
INCIDENT DETAILS -
TYPE
Data Exfiltration
MOTIVATION
Data Exfiltration
IMPACT
Data Compromised: Sensitive Information
DATA BREACH
Type Of Data Compromised: Sensitive Information

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for AnyDesk Software ?
?
What was AnyDesk Software's A.I Rankiteo Cyber Score in May 2026 ?
?
What was AnyDesk Software's A.I Rankiteo Cyber Score in April 2026 ?
?
What was AnyDesk Software's A.I Rankiteo Cyber Score in March 2026 ?
?
What was AnyDesk Software's A.I Rankiteo Cyber Score in February 2026 ?
?
What was AnyDesk Software's A.I Rankiteo Cyber Score in January 2026 ?
?
What was AnyDesk Software's A.I Rankiteo Cyber Score in December 2025 ?
?
What was AnyDesk Software's A.I Rankiteo Cyber Score in November 2025 ?
?
What was AnyDesk Software's A.I Rankiteo Cyber Score in October 2025 ?
?
What was AnyDesk Software's A.I Rankiteo Cyber Score in September 2025 ?
?
What was AnyDesk Software's A.I Rankiteo Cyber Score in August 2025 ?
?
What was AnyDesk Software's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on AnyDesk Software's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with AnyDesk Software ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view AnyDesk Software's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?