Malware
TeamSpy
Also known as: TVRAT · TVSPY · TeamViewerENT
Indicators of Compromise 1
MITRE ATT&CK TTPs 4
Source Articles
Extradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousands
A Russian national, Searzhudin Tamirlanovich Aktulaev, has been extradited and charged by the U.S. Department of Justice for orchestrating a malware campaign between 2016 and 2017 that targeted users of a major freelance platform. The campaign involved sending malicious Excel attachments that prompted victims to enable macros, which then downloaded either TVRAT (a TeamViewer-based RAT) or DarkVNC malware. These malware variants provided remote access to infected systems and exfiltrated stolen data, including e-commerce credentials and PII, to a U.S.-hosted command-and-control server. The attack exploited DLL search order hijacking to load a malicious msimg32.dll, allowing stealthy persistence and remote control.
hacker-news ·8h ago
US charges Russian for infecting 80,000 freelancers with malware
A Russian national, Searzhudin Tamirlanovich Aktulaev, has been indicted for conducting a phishing campaign between June 2016 and November 2017 that infected approximately 80,000 freelancers with TVRAT and DarkVNC malware. The attacker used 255 fake accounts on a freelance platform to send malicious Excel attachments containing macros, which downloaded malware enabling remote access via TeamViewer and VNC Viewer. The malware exfiltrated stolen data, including e-commerce credentials and personally identifiable information, to command-and-control servers paid for with virtual currency, with thousands of infected systems in the U.S., particularly in the Northern District of California.
bleeping-computer ·8h ago