Ransomware Actor Uses TeamViewer to Gain Initial Access to Networks
ID: 0558e05d-286e-5390-aab4-fb34565f0b46
STIX ID: report--0558e05d-286e-5390-aab4-fb34565f0b46
Feed Name: Dark Reading
Huntress observed two failed attempts to deploy ransomware (apparently built from a leaked LockBit 3.0 builder) after attackers obtained initial access to endpoints via TeamViewer; logs indicate the same actor accessed two separate endpoints, likely using compromised or brokered credentials. The report outlines past misuse of TeamViewer for malware, cryptomining, and data exfiltration, discusses possible credential theft vectors, and summarizes TeamViewer security recommendations (strong passwords, 2FA, allow-lists, updates).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
