logo

Ransomware Actor Uses TeamViewer to Gain Initial Access to Networks

ID: 0558e05d-286e-5390-aab4-fb34565f0b46

STIX ID: report--0558e05d-286e-5390-aab4-fb34565f0b46

Feed Name: Dark Reading

Threat Score
55/100

Date Published: 2024-01-19

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Huntress observed two failed attempts to deploy ransomware (apparently built from a leaked LockBit 3.0 builder) after attackers obtained initial access to endpoints via TeamViewer; logs indicate the same actor accessed two separate endpoints, likely using compromised or brokered credentials. The report outlines past misuse of TeamViewer for malware, cryptomining, and data exfiltration, discusses possible credential theft vectors, and summarizes TeamViewer security recommendations (strong passwords, 2FA, allow-lists, updates).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.