TeamSpy Malware
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
The attackers, known as TeamSpy, used the popular remote access program TeamViewer and a specially crafted malware to steal documents and encryption keys from users.
Present day TeamSpy uses social engineering attacks to lure users into installing the TeamSpy malware. The malware uses Dynamic Link Library (DLL) hijacking to execute unauthorised actions through legitimate software.
The attack chain begins with a spam email with a .zip attachment. If a user opens the zip archive, it executes the accompanying .exe file which drops the TeamSpy malware onto the user's system as a malicious DLL.
The TeamSpy malware includes various components in the otherwise legitimate TeamViewer application, two of which are a keylogger and a TeamViewer VPN which suggests the confidentiality of an affected system would be fully compromised.
Remediation steps
Last edited: 17 February 2020 11:40 am