Ransomware Deployment Attempts Via TeamViewer | Huntress
ID: 8520ccc6-4eee-525a-a1d0-86094ed50a9f
STIX ID: report--8520ccc6-4eee-525a-a1d0-86094ed50a9f
Feed Name: Huntress Blog
Huntress SOC investigated two minimally impactful ransomware incidents attributed to remote access via TeamViewer that executed a DLL via rundll32 from a desktop batch file; one endpoint had limited file encryption while the other was prevented from further impact by security software. The report maps the activity to MITRE ATT&CK (T1133, T1059.003, T1486), provides IOCs including the TeamViewer source name WIN-8GPEJ3VGB8U and LB3_Rundll32_pass.dll (SHA256:60ab8cec19fb2d1ab588d02a412e0fe7713ad89b8e9c6707c63526c7768fd362), and advises stronger asset/application inventory and remote-access controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
