TeamViewer abused to install ransomware on computers (update)

Users on BleepingComputer report TeamViewer is abused to install ransomware on computers. Although it's unclear how the cyber criminals gain access to TeamViewer, the login to the computer and the activation of the ransomware is clearly visible in TeamViewer's logs.

teamviewer

It might be possible that hackers gain access by bruteforcing passwords, abusing zero-day vulnerabilities or by resetting passwords through email addresses obtained by other hacks. Whatever method they use, once they have access to the computer they upload a file to the desktop called surprise.exe. This is the actual ransomware which encrypts files and adds the extension .surprise.

A successful attempt looks like this in the TeamViewer logs:

03:00:27.983  1868  5664 S0   Estimated RTT to 479440875: 321 ms, Reliability: 3, Carrier: 2
03:02:35.931  4788  3996 G1   - File transfer request from -------- (xxx xxx xxx) allowed
03:02:36.400  4788  3996 G1   - Views folder <root drives>
03:02:37.603  4788  3996 G1   - Views folder <root drives>
03:02:41.666  4788  3996 G1   - Views folder C:\Users\MyUserName\Desktop\
03:02:48.932  4788  3996 G1   - Processing file transfer...
03:02:48.947  4788  3996 G1   - Write file C:\Users\MyUserName\Desktop\surprise.exe
03:02:51.197  4788  3996 G1   - File transfer finished.
03:02:51.197  4788  3996 G1   - Views folder C:\Users\MyUserName\Desktop\
03:02:53.010  4788   300 G1   Ending CFileTransferThreadServer...
03:02:53.010  4788   300 G1   The CFileTransferThreadServer has ended.
03:02:53.010  4788  3996 G1   - File transfer server shut down.

The ransomware is a variant of the open-source ransomware called EDA2 which was developed by a Turkish researcher. The cyber criminals simply make small changes to the EDA2 proof-of-concept of which the source code is readily available.

While the actual source of the issue isn't clear it's advisable to uninstall TeamViewer when not used. If you want to keep it, then make sure to upgrade to the latest version. When using unattended mode it's important to use a strong password.

Update: TeamViewer has reached out to us on Twitter:

No posts to display