Researchers and government defenders have linked multiple campaigns to SpyAgent—also tracked as TeamSpy, TVRAT, TeamBot, and Sheldor—a long-running malware family that hijacks legitimate remote administration tools to gain covert control of Windows systems. Early and later variants abused TeamViewer by delivering malicious Office documents through targeted spam or job-application lures, then installing signed TeamViewer components alongside a rogue DLL and configuration files. The malware used DLL search order hijacking and DLL side-loading to hide the remote-access interface, suppress user prompts, steal the victim’s TeamViewer ID, and enable data theft, arbitrary command execution, and persistent backdoor access while blending traffic with legitimate remote-support activity.
More recent activity showed the operators adapting both tooling and delivery to reduce detection. Deep Instinct reported that 2022 campaigns shifted from TeamViewer to Safib Assistant, a similar remote administration product, and used oversized droppers and inflated DLLs to evade scanning limits before moving to Inno Setup bundles containing the legitimate tool and SpyAgent alone. HP Wolf Security separately documented a blocked intrusion at a financial organization in which a resume-themed Word document launched TeamViewer and regsvr32.exe to execute a malicious DLL, with infrastructure tied to domains including morteson[.]com, creatorz123[.]top, 123faster[.]top, and thief[.]lol. The reporting shows a sustained espionage-oriented threat that continues to repurpose trusted remote-access software as malware delivery and command-and-control cover.

Pull IOCs and campaign context straight into your stack.
10 events from the most recent confirmed update back to the earliest known activity.
In June 2022, the campaign dropped its cryptocurrency theme and moved back to Inno Setup droppers that bundled SpyAgent with legitimate Safib Assistant, reducing detection by appearing more benign.
In May 2022, SpyAgent operators switched to oversized droppers larger than 700MB and inflated DLLs above 1GB with zero-byte overlays to evade scanning limits in security tools and repositories.
A 2021 report showed SpyAgent moving away from TeamViewer hijacking to abusing Safib Assistant, a Russian TeamViewer-like remote administration tool, with fake cryptocurrency applications used as lures.
In January 2020, attackers targeted a financial organization with a malicious resume document uploaded to a legitimate job portal; when opened by an HR employee, it delivered a TVRAT/Spy-Agent variant abusing TeamViewer side-loading.
A 2016 report described Spy-Agent using DLL search order hijacking with TeamViewer 6.0, continuing the documented evolution of the malware family.
TeamSpy first appeared in 2013, and white papers from CrySyS Lab and Kaspersky Lab documented the malware's abuse of TeamViewer through DLL search order hijacking.
A 2011 report described the Sheldor malware using DLL search order hijacking with TeamViewer 5.0, an early documented precursor to later TeamSpy/SpyAgent activity.
The U.S. Department of Justice charged Searzhudin Tamirlanovich Aktulaev over an alleged 2016–2017 campaign that used fraudulent freelance-platform accounts and malicious Excel macros to distribute TVRAT/TeamSpy and DarkVNC to thousands of victims. Aktulaev was arrested in Cyprus in May 2025, extradited to the United States, and remanded to federal custody after appearing in San Francisco federal court; the allegations remain unproven and he denies guilt.
Deep Instinct confirmed that malware bundled with Safib Assistant was SpyAgent by interacting with active command-and-control infrastructure, including thief[.]lol resolving to 185.125.206[.]172 during analysis.
Heimdal Security reported that TeamSpy had resurfaced in a targeted spam campaign delivering malicious Excel attachments that installed the malware alongside TeamViewer components.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 25 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
6 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcelearn.microsoft.com
Open sourcedeepinstinct.com
Open sourcethreatresearch.ext.hp.com
Open sourceblog.avast.com
Open sourcecyber.nj.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.