TeamViewer abused to breach networks in new ransomware attacks
ID: f19f3247-bc25-5044-b0ee-475ded1e6638
STIX ID: report--f19f3247-bc25-5044-b0ee-475ded1e6638
Feed Name: Bleeping Computer
Threat Score
Ransomware actors are leveraging compromised or weakly secured TeamViewer accounts to access enterprise endpoints and deploy LockBit-3-style encryptors (password-protected DLLs launched via rundll32) using a dropped PP.bat file; Huntress observed multiple attempts with one infection contained and another blocked by antivirus, and analysis ties the samples to variants built from a leaked LockBit 3.0 builder.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
