logo

Trojanized Application Preying on TeamViewer Users

ID: 1d386156-493d-527b-9227-5cb2ab6ee3ce

STIX ID: report--1d386156-493d-527b-9227-5cb2ab6ee3ce

Feed Name: Cyble Blog

Threat Score
74/100

Date Published: 2023-07-29

Date Updated: 2026-07-20

...
...

This report details a trojanized TeamViewer installer that installs njRAT (Bladabindi) alongside the legitimate TeamViewer binary, describing its drop/install behavior, persistence mechanisms (startup copy and Run keys), keylogging and system information collection, registry and firewall modifications, hardcoded mutex and C2, and provides hashes and a C2 URL as IOCs along with mitigation advice.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.