Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
The communication via the TeamViewer chat allows for the basic backdoor functionalities to be performed: applist , wcmd , ver , os , vpn , locale , time , webcam , genid .
This macro then downloaded one of two malware types: a variant of TVRAT (also known as TeamSpy) or DarkVNC.
TVRAT allows its users to exploit a vulnerability in remote access tool TeamViewer and take over a victim’s device. DarkVNC... exploited a bug in... VNC Viewer.
If we look inside the malicious macro, we can see slightly obfuscated strings, usually split into one or more substrings, which are later concatenated.
Although the attachment of the downloaded is a PNG, it is actually an EXE file... most of the files are regular, digitally signed TeamViewer binaries, with the exception of two files - msimg32.dll and tvr.cfg.
The tools ... check for the existence of specific files, windows registry entries ... For example, SIG2 includes System\CurrentControlSet\Control\CrashImage and SIG23 includes software\microsoft\NetWin.
They check for the existence of specific files, windows registry entries, and other signs ... For example, this script looks for the existence of an actual file “winver32.exe” in the very specific $docsandsettings\\$subkey\\Application Data\\winver32.exe path.
Thousands of computers infected with TVRAT were calling back to a command-and-control domain hosted in the U.S. The infected machine then reports its TeamViewer ID to a C2 server.
Thousands of computers infected by the TVRAT malware were 'calling back' to a command-and-control domain hosted in the United States.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
TeamSpy is a backdoor/RAT that infects victims via malicious Excel macro attachments, installs legitimate TeamViewer components alongside a malicious sideloaded DLL, hides the TeamViewer interface through extensive API hooking, exfiltrates the TeamViewer ID to a C2 server, and enables attackers to remotely control the infected machine, send commands via TeamViewer chat, steal data, and execute arbitrary programs.
An espionage malware family associated with SIG39 via MS QAG registry keys U11 and U12.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.