TVRAT, commonly known as TeamSpy and also referred to as TVSPY, is a Windows remote-access trojan that abuses legitimate TeamViewer components to provide covert remote control of compromised systems. Observed TeamSpy implementations use DLL side-loading or search-order hijacking against signed TeamViewer binaries, conceal TeamViewer user-interface elements, and provide operators with the compromised host's TeamViewer identifier for remote access. Reported functionality includes remote control, file transfer, collection and exfiltration of victim data, and, in some variants, access to the microphone and webcam. TVRAT has been delivered through socially engineered documents, including job-application lures and malicious Excel attachments that require victims to enable macros; it has also appeared as a follow-on payload in phishing and cryptocurrency-themed lure campaigns. In a U.S. criminal case, prosecutors alleged that TVRAT and DarkVNC were distributed through fraudulent accounts on a freelance-employment platform and used to collect victim data for subsequent fraud. TVRAT has also been deployed as a secondary payload following Ursnif infections.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
Opening an attachment prompted the recipient to enable or execute an embedded macro. If the user complied, the macro downloaded malware from the internet.
TVRAT allows its users to exploit a vulnerability in remote access tool TeamViewer and take over a victim’s device. DarkVNC... exploited a bug in... VNC Viewer.
41 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote-access malware that allegedly enabled the conspirators to control infected computers, steal information, and transfer stolen data to command-and-control servers. It incorporated or abused components associated with TeamViewer.
A remote-access trojan used to remotely control infected systems and exfiltrate stolen data to command-and-control servers.
Remote-access malware that abuses legitimate TeamViewer components. It uses DLL hijacking via a malicious msimg32.dll, hides the TeamViewer interface, reports the victim machine ID to operators, and enables remote access using a predefined password. It also steals information and exfiltrates it to a C2 server.
A remote-access trojan allegedly delivered through malicious Excel macro attachments. It provides remote control of infected computers through TeamViewer and exfiltrates victim data to command-and-control infrastructure for collection and subsequent fraud or other criminal activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.