TeamViewer is a legitimate remote administration and remote support application for Windows and other platforms that is frequently abused by threat actors as an access-enabling component rather than as malware in its standard form. In intrusion reporting it commonly appears as a signed remote access tool installed after initial compromise to provide interactive control, persistence, and hands-on-keyboard access. Threat actors have used it in financially motivated intrusions, telephone-oriented social engineering schemes, ransomware operations, and espionage campaigns.
In multiple campaigns, attackers installed legitimate TeamViewer on compromised Windows systems to maintain persistent remote access, support lateral operations, or supplement other tooling. It has been observed alongside post-compromise activity such as credential theft, privilege escalation, and data theft, including use by ransomware operators and initial access brokers. TeamViewer has also been delivered as part of phishing-driven infection chains and as a follow-on tool in social engineering workflows intended to gain remote control of victim devices.
A distinct malicious use case involves modified TeamViewer clients employed by the North Korea-linked Kimsuky threat actor. Kimsuky used a patched TeamViewer 5 client as a command-and-control channel and remote control component in espionage operations targeting South Korean organizations and policy-focused entities. Those operations paired the modified client with malware capable of persistence via Windows services, keylogging, host reconnaissance, defense evasion through disabling security controls, and exfiltration of collected data. Related reporting also describes TeamViewer being used in conjunction with loaders or droppers that sideload malicious DLLs, as well as being embedded in broader malware ecosystems such as MineBridge-enabled intrusions.
Because TeamViewer is legitimate software, detections involving it require context: its presence may indicate benign administration, attacker-installed remote access, or a modified client repurposed for covert command and control. High-confidence malicious characterization applies when TeamViewer is patched, bundled with malware, installed without authorization, or used as part of a documented intrusion set.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"We also observed the installation of additional remote access tools, such as TeamViewer and LogMeIn."
"We also observed the installation of additional remote access tools, such as TeamViewer and LogMeIn."
"We also observed the installation of additional remote access tools, such as TeamViewer and LogMeIn."
"Kimsuky has used a modified TeamViewer client, version 5.0.9104, for Command and Control"
20 distinct techniques documented for this family, organized by ATT&CK tactic.
it appears that the intruder authenticated to the network while it was monitored by personnel
AutoHotkeyU32.ahk→an AHK script which sends a POST request to the C&C server and can receive additional AHK script URLs to download and execute.
Once the macros are enabled, two files are extracted from hex encoded cells within the XLSM document.
it appears that the intruder authenticated to the network while it was monitored by personnel
hinfo.ahk : Sends the victim’s username and computer information to the C&C server.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A legitimate remote access tool abused in TOAD attacks and observed prominently in network detections related to malicious RMM activity.
Legitimate remote administration software abused by attackers to maintain persistent interactive access to compromised environments.
Commercial remote access software abused by the actor after obtaining credentials, used to maintain access and support movement within the environment.
Legitimate remote access tool abused by intruders for interactive access/persistence; referenced as used in Black Basta activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.