• Skip to main content
  • Skip to header right navigation
  • Skip to site footer
iGuRu

iGuRu

Real-time Technology News. Opinions & Tweaks

  • / news
  • / infosec
  • / tools
  • / tweaks
  • / dummies
  • / opinions
  • / support
home / News / TeamViewer: software hides remote connections

TeamViewer: software hides remote connections

23/04/2019 15:38 by giorgos

A new targeted attack was detected through TeamViewer, which aimed at stealing financial information from government and economic targets across Europe and beyond.

Check Point researchers announced on Monday that the attacks targeted government and financial officials, as well as representatives of various embassies in Europe, Nepal, Kenya, Liberia, Lebanon, Guyana and Bermuda.teamviewer - TeamViewer: software hides remote connections

The attack began with a typical phishing e-mail containing a malicious attachment claiming to be a "top secret" document from the United States.

The subject line stated "Military Financing Program" and the .XLSM document bore the US State Department logo.
screenshot 2019 04 23 at 12 33 35 - TeamViewer: software hides remote connections

So if someone opened the document and activated the macros, two files came out - a regular AutoHotkeyU32.exe program and a malicious TeamViewer DLL.

AutoHotkeyU32 was used to send a POST request to the intruder's command and control (C&C) server, but also to download more malicious scripts capable of capturing screenshots of the target computer, stealing information, and then sending it to the attacker. .

TeamViewer is often used by businesses for remote PC access. However, due to its capabilities, the software is also used by scammers to gain access to remote systems.

The malicious variant with TeamViewer DLL provided attackers with modified functionality, and hid any connection to TeamViewer. So the victims did not know that someone was connected to their computer.

The main targets of this attack as mentioned above were public financial sector players and according to the researchers the would-be hacker was a Russian.

_________________

  • GR and EL domains: Attack to the Greek Internet Name Registry
  • Windows 10 Fall Creators support fee immediately upgrade
  • Mathesis: Ancient Greek Technology 1 (Basic Technologies)
  • Edge with Chromium allows video streaming on 4K
  • Mark Zuckerberg: help from regulators & governments
TeamViewer: software hides remote connections was last modified: 23 April, 2019, 3: 38 mm by giorgos

Subscribe to our newsletter

no spam

spread the news

  • Facebook
  • Twitter
  • Reddit
  • Printing
  • Email

Read them Technology News from all over the world, with the validity of iGuRu.gr

Follow us on Google News


Competition: Newstag: check, Check Point, chromium, Edge Chromium, Mathesis

You May Also Like

Microsoft warns of Adrozek infecting browsers
Introduction to web development with HTML5, CSS3, Javascript
Microsoft Edge displays pdfs every two pages

About Us giorgos

George still wonders what he's doing here ...

Previous Post: « Microsoft: Paint will continue to run
Next Post: The April update for Windows also has problems with McAfee software »

Reader Interactions

Comment Policy:

IGuRu.gr does not publish the comments immediately. Malicious comments, comments that include ads, or comments that are offensive are deleted without notice. We do not adopt the opinions expressed by our readers.
Your comments will be displayed after approval by the administrators


Leave your comment
Ακύρωση απάντησης

Your email address is not published. Τα υποχρεωτικά πεδία σημειώνονται με *

 

 © 2021 · iGuRu.gr · ☢ · Keep It Simple Stupid Genesis theme

about  ·   get in touch  ·  rss  ·  sitemap  ·  cough

loadingCancel
Could not post post - check your email address!
Email verification failed, please try again
Your blog can not post posts via email.