logo

TeamViewer abused to breach networks in new ransomware attacks

ID: f19f3247-bc25-5044-b0ee-475ded1e6638

STIX ID: report--f19f3247-bc25-5044-b0ee-475ded1e6638

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-01-18

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Ransomware actors are leveraging compromised or weakly secured TeamViewer accounts to access enterprise endpoints and deploy LockBit-3-style encryptors (password-protected DLLs launched via rundll32) using a dropped PP.bat file; Huntress observed multiple attempts with one infection contained and another blocked by antivirus, and analysis ties the samples to variants built from a leaked LockBit 3.0 builder.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.