logo

Ransomware Deployment Attempts Via TeamViewer | Huntress

ID: 8520ccc6-4eee-525a-a1d0-86094ed50a9f

STIX ID: report--8520ccc6-4eee-525a-a1d0-86094ed50a9f

Feed Name: Huntress Blog

Threat Score
65/100

Date Published: 2024-04-12

Date Updated: 2026-04-28

...
...

Huntress SOC investigated two minimally impactful ransomware incidents attributed to remote access via TeamViewer that executed a DLL via rundll32 from a desktop batch file; one endpoint had limited file encryption while the other was prevented from further impact by security software. The report maps the activity to MITRE ATT&CK (T1133, T1059.003, T1486), provides IOCs including the TeamViewer source name WIN-8GPEJ3VGB8U and LB3_Rundll32_pass.dll (SHA256:60ab8cec19fb2d1ab588d02a412e0fe7713ad89b8e9c6707c63526c7768fd362), and advises stronger asset/application inventory and remote-access controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.