Trojanized Application Preying on TeamViewer Users
ID: 1d386156-493d-527b-9227-5cb2ab6ee3ce
STIX ID: report--1d386156-493d-527b-9227-5cb2ab6ee3ce
Feed Name: Cyble Blog
Threat Score
This report details a trojanized TeamViewer installer that installs njRAT (Bladabindi) alongside the legitimate TeamViewer binary, describing its drop/install behavior, persistence mechanisms (startup copy and Run keys), keylogging and system information collection, registry and firewall modifications, hardcoded mutex and C2, and provides hashes and a C2 URL as IOCs along with mitigation advice.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
