TVRat, also referred to as Spy-Agent and sometimes described as TeamViewer RAT, is a Windows remote access Trojan that provides attackers with interactive control over compromised systems. It has been observed as a follow-on payload in multi-stage intrusion chains and malware campaigns, including financially themed and cryptocurrency-themed social-engineering operations, as well as post-compromise deployments alongside tools such as Cobalt Strike and Ursnif. TVRat has also been linked to intrusion activity targeting financial organizations.
The malware’s core functionality includes remote control of an infected PC, file transfer, and surveillance through access to the victim’s microphone and webcam. Operational reporting also places it in broader intrusion chains that delivered backdoor access and user-information theft. In observed incidents, TVRat was deployed after an initial downloader or document-based infection stage, giving operators persistent remote access for hands-on-keyboard activity.
TVRat delivery has been documented through multiple vectors. One observed chain used a malicious Microsoft Word document disguised as a resume and distributed through a legitimate job portal, allowing the attack to bypass email-centric defenses. Another campaign used cryptocurrency lures and malicious websites to socially engineer victims into downloading malware, with TVRat delivered as a second-stage payload. It has also appeared as a later-stage payload in spearphishing-driven Ursnif infections that hijacked existing email threads and used cloud-hosted links to deliver archives and script-based droppers.
A notable execution pattern involved abuse of legitimate TeamViewer components and DLL sideloading. In one investigated intrusion, Microsoft Word launched a legitimate TeamViewer executable while malicious DLLs were written to disk and executed via regsvr32, resulting in sideloading of a rogue library into the TeamViewer process. This tradecraft supports defense evasion and blends malicious activity with trusted remote-administration software.
TVRat is best characterized as a remote access Trojan used for post-exploitation and covert remote administration on Windows systems. Its observed use across varied delivery chains and its reliance in some cases on legitimate remote-access tooling make it a flexible payload for espionage, surveillance, and broader intrusion enablement.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
The delivery method of the downloader, a malicious Microsoft Word document, was notable because the attacker disguised it as a resume and then uploaded it to a legitimate job portal website. It was subsequently downloaded and opened by a member of the target organisation’s human resources department.
some samples proceeded further... beaconing to the Ursnif C2 at 8.208.90.28
a DNS query to creatorz123[.]top... indicative of command and control (C2) check-in activity... approximately 26 seconds after the triggering high severity event an HTTPS session was established to 123faster[.]top... roughly every minute a CONNECT method request occurred to that domain, indicating that this session is likely the C2 connection used by the threat actor.
41 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An additional payload downloaded and executed by the campaign's downloader; the content and detections indicate it functions as a RAT/backdoor payload.
A remote access trojan delivered via a malicious Word-document downloader. In this case it was executed through regsvr32 and also side-loaded as a malicious DLL into a legitimate TeamViewer executable, then established C2 communications with attacker-controlled domains.
A remote access trojan delivered as a follow-on payload after Ursnif. The content states it uses TeamViewer to provide remote access to the attacker.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.