Skip to main content

TeamSpy Malware

The TeamSpy malware made the headlines in 2013 when security researchers discovered a decade long cyber espionage campaign that targeted high-level political figures and industrial entities in Eastern Europe.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

The TeamSpy malware made the headlines in 2013 when security researchers discovered a decade long cyber espionage campaign that targeted high-level political figures and industrial entities in Eastern Europe.

Affected platforms

The following platforms are known to be affected:

Threat details

The attackers, known as TeamSpy, used the popular remote access program TeamViewer and a specially crafted malware to steal documents and encryption keys from users.

Present day TeamSpy uses social engineering attacks to lure users into installing the TeamSpy malware. The malware uses Dynamic Link Library (DLL) hijacking to execute unauthorised actions through legitimate software.

The attack chain begins with a spam email with a .zip attachment. If a user opens the zip archive, it executes the accompanying .exe file which drops the TeamSpy malware onto the user's system as a malicious DLL.

The TeamSpy malware includes various components in the otherwise legitimate TeamViewer application, two of which are a keylogger and a TeamViewer VPN which suggests the confidentiality of an affected system would be fully compromised.


Remediation steps

Type Step
  • Ensure software is kept up to date.
  • Avoid bundled software installers.
  • Ensure anti-virus and anti-malware definitions are kept up to date.
  • Never open email attachments from unknown sources.

Last edited: 17 February 2020 11:40 am