{"id":33379,"date":"2024-02-29T00:01:06","date_gmt":"2024-02-28T23:01:06","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=33379"},"modified":"2024-02-28T18:49:06","modified_gmt":"2024-02-28T17:49:06","slug":"microsoft-defender-blocks-anydesk-clients-since-28-february-2024","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2024\/02\/29\/microsoft-defender-blocks-anydesk-clients-since-28-february-2024\/","title":{"rendered":"Microsoft Defender blocks Anydesk clients (since 28 February 2024)"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"margin: 0px 10px 0px 0px;\" title=\"Stop - Pixabay\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2021\/06\/Stop01.jpg\" alt=\"Stop - Pixabay\" width=\"149\" height=\"149\" align=\"left\" \/>[<a href=\"https:\/\/www.borncity.com\/blog\/2024\/02\/28\/microsoft-defender-blockt-anydesk-clients-28-februar-2024\/\" target=\"_blank\" rel=\"noopener\">German<\/a>]Brief information for everyone. I have just heard from blog readers that the clients of the remote maintenance provider AnyDesk will probably be blocked by Microsoft Defender under Windows from today (28 February 2024). The whole thing is related to the hack of the provider AnyDesk, in which certificates may have been lost. Here is a brief overview, what you need to know so far.<\/p>\n<p><!--more--><\/p>\n<h2>Reader reports about blocked clients<\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vg06.met.vgwort.de\/na\/4dad1bc1a3e043378c44e0806ac39e9f\" alt=\"\" width=\"1\" height=\"1\" \/>Blog reader Peter H. from Germany contacted me yesterday via email and reported that Windows Defender was blocking AnyDesk clients with the latest signature update. His email states:<\/p>\n<blockquote><p>Nun m\u00f6chte ich mit Dir folgende Erfahrung teilen: Seit HEUTE (bzw. letzten Defender Signatur Update) blockt Defender alle Downloads als auch die Ausf\u00fchrung von Anydesk (aktuell v7.0.15) und stuft diese als PUA.Win32.Softcnapp ein.<\/p><\/blockquote>\n<p><a href=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2024\/02\/image-28.png\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone\" title=\"Defender blocks AnyDesk\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2024\/02\/image-28.png\" alt=\"Defender blocks AnyDesk\" width=\"682\" height=\"298\" \/><\/a><br \/>\nDefender blocks AnyDesk, <a href=\"https:\/\/i.postimg.cc\/D028qzXZ\/image.png\" target=\"_blank\" rel=\"noopener\">Click to zoom<\/a><\/p>\n<p>Peter wrote that the signature visible in the screenshot below is used in Defender, so its signature files are up to date:<img decoding=\"async\" title=\"Defender-Signatur\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2024\/02\/image001.png\" alt=\"Defender Signature\" \/><\/p>\n<p>German blog reader Harald has also posted <a href=\"https:\/\/www.borncity.com\/blog\/2024\/02\/23\/anydesk-ist-down-was-ist-da-los-23-feb-2024\/#comment-174666\" target=\"_blank\" rel=\"noopener\">a comment<\/a> in my German blog, stating that \"since today, Windows Defender has started to detect the latest AnyDesk clients with the latest signature and report them as potentially unwanted programs\". Karsten has also reported this in the discussion area. I'll pull it out separately, as I delete the discussion entries sporadically.<\/p>\n<blockquote><p>The new anyDesk clients are being blocked today by Microsoft Defender as an unwanted app.<br \/>\n'PUA:Win32\/Softcnapp' is reported as the reason.<\/p><\/blockquote>\n<p>We are talking about the newly released clients that have been digitally signed with a new digital certificate from AnyDesk GmbH. Karsten also referred to the reddit.com post <a href=\"https:\/\/www.reddit.com\/r\/AnyDesk\/comments\/1b229m0\/anydesk_custom_client_is_blocked_by_microsoft\/\" target=\"_blank\" rel=\"noopener\">Anydesk custom client is blocked by Microsoft Defender<\/a>, where another user confirms the Defender's behavior.Hello,<\/p>\n<blockquote><p>since this morning, Anydesk custom client, from my.anydesk 1 and 2 (.exe and .msi) is blocked by Defender.<\/p>\n<p>Defender detected and terminated active 'PUA:Win32\/Softcnapp' in process 'AnyDesk.exe' during a scheduled scan<\/p>\n<p>Anybody have the same situation ?<\/p><\/blockquote>\n<p>Within the thread, other users confirm the problem. One user <em>doud_doud<\/em> quotes an answer from AnyDesk support:<\/p>\n<blockquote><p>Sorry for this inconvenience. Our team is actively investigating the root cause of this issue.<\/p>\n<p>The current solution, if nothing is configured and a false positive notification arises, would be to manually add an exception\/rule for AnyDesk.<\/p>\n<p>There is no risk in using AnyDesk. Therefore, you can download and install AnyDesk safely.<\/p>\n<p>We appreciate your patience and understanding.<\/p><\/blockquote>\n<p>They have now run into real problems when the AnyDesk client is now blocked as unwanted on many systems and moved to quarantine. The recommendation: Define an exception for the client in Defender so that it is no longer blocked. The howler of the month is \"There is no risk in using AnyDesk. Therefore, you can download and install AnyDesk safely.\".<\/p>\n<h2>The background<\/h2>\n<p>The background to all this is probably that the provider AnyDesk was the victim of a cyberattack on its production systems in December 2023. However, the whole thing did not come to light until the beginning of February 2024 &#8211; possibly also due to the reporting here in the blog (see links at the end of the article).<\/p>\n<p>AnyDesk could not rule out the possibility that the keys for the certificates used to digitally sign files had been lost. The old certificates were therefore revoked and the provider was busy providing new clients with updated digital signatures in February.<\/p>\n<p>Perhaps something got into the binary files when \"building the new clients\", causing Defender to regard the whole thing as undesirable. We will have to wait and see whether AnyDesk can rectify the situation with Microsoft &#8211; if the AnyDesk client is still to be used at all.<\/p>\n<p><strong>Articles:<\/strong><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2024\/02\/03\/anydesk-confirmed-they-have-been-hacked-in-january-2024-production-systems-affected\/\">AnyDesk confirmed, they have been hacked in January 2024, Production systems affected<\/a>\u00a0\u2013 Part 1<br \/>\n<a href=\"https:\/\/borncity.com\/win\/2024\/02\/03\/anydesk-hack-undercover-more-information-and-thoughts-part-2\/\">AnyDesk hack undercover \u2013 more information and thoughts<\/a>\u00a0\u2013 Part 2<br \/>\n<a href=\"https:\/\/borncity.com\/win\/2024\/02\/04\/anydesk-hack-undercover-suspicious-cases-and-more-part-3\/\" target=\"_blank\" rel=\"noopener\">AnyDesk hack undercover \u2013 Suspicious cases and more<\/a>\u00a0\u2013 Part 3<br \/>\n<a href=\"https:\/\/borncity.com\/win\/2024\/02\/04\/anydesk-hack-undercover-access-data-offered-for-sale-part-4\/\" target=\"_blank\" rel=\"noopener\">AnyDesk hack undercover \u2013 Access data offered for sale<\/a>\u00a0\u2013 Part 4<br \/>\n<a href=\"https:\/\/borncity.com\/win\/2024\/02\/05\/anydesk-hack-a-review-part-5\/\">AnyDesk hack \u2013 A review<\/a>\u00a0\u2013 Part 5<br \/>\n<a href=\"https:\/\/borncity.com\/win\/2024\/02\/06\/anydesk-hack-review-of-the-german-cert-bsi-report-part-6\/\">AnyDesk hack \u2013 Review of the German CERT BSI report<\/a>\u00a0\u2013 Part 6<br \/>\n<a href=\"https:\/\/borncity.com\/win\/2024\/02\/07\/anydesk-hack-notes-on-exchanging-certificates-for-customs-clients-7-x-part-7\/\">AnyDesk hack \u2013 Notes on exchanging certificates for Customs clients 7.x<\/a>\u00a0\u2013 Part 7<br \/>\n<a href=\"https:\/\/borncity.com\/win\/2024\/02\/07\/anydesk-hack-more-details-faq-from-feb-5-2024-part-8\/\" target=\"_blank\" rel=\"noopener\">AnyDesk hack \u2013 more details (FAQ from Feb. 5, 2024)<\/a>\u00a0\u2013 Part 8<br \/>\n<a href=\"https:\/\/borncity.com\/win\/2024\/02\/08\/anydesk-hack-already-noticed-on-december-20-2023-part-9\/\">AnyDesk hack already noticed on December 20, 2023?<\/a>\u00a0\u2013 Part 9<br \/>\n<a href=\"https:\/\/borncity.com\/win\/2024\/02\/09\/anydesk-hack-confirmed-as-of-december-2023-old-certificate-recalled-part-10\/\">AnyDesk hack confirmed as of December 2023; old certificate recalled<\/a>\u00a0\u2013 Part 10<br \/>\n<a href=\"https:\/\/borncity.com\/win\/2024\/02\/14\/anydesk-hack-revoke-chaos-with-old-certificates-part-11\/\">AnyDesk hack: Revoke chaos with old certificates?<\/a>\u00a0\u2013 Part 11<br \/>\n<a href=\"https:\/\/borncity.com\/win\/2024\/02\/20\/anydesk-hack-newly-signed-clients-availalbe-what-are-your-experiences-part-12\/\">AnyDesk hack: Newly signed clients available; what are your experiences?<\/a>\u00a0\u2013 Part 12<\/p>\n<p><a href=\"https:\/\/www.borncity.com\/blog\/2024\/01\/25\/strung-bei-anydesk-jemand-betroffen\/\" target=\"_blank\" rel=\"noopener\">St\u00f6rung bei AnyDesk, jemand betroffen?<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2024\/02\/02\/anddesk-be-careful-in-using\/\" rel=\"bookmark\">AnyDesk: Be careful in using that remote support software<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]Brief information for everyone. I have just heard from blog readers that the clients of the remote maintenance provider AnyDesk will probably be blocked by Microsoft Defender under Windows from today (28 February 2024). The whole thing is related to &hellip; <a href=\"https:\/\/borncity.com\/win\/2024\/02\/29\/microsoft-defender-blocks-anydesk-clients-since-28-february-2024\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[580,1547,2],"tags":[773,1544,194],"class_list":["post-33379","post","type-post","status-publish","format-standard","hentry","category-security","category-software","category-windows","tag-defender","tag-software","tag-windows"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/33379","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=33379"}],"version-history":[{"count":1,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/33379\/revisions"}],"predecessor-version":[{"id":33380,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/33379\/revisions\/33380"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=33379"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=33379"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=33379"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}