Users on BleepingComputer report TeamViewer is abused to install ransomware on computers. Although it's unclear how the cyber criminals gain access to TeamViewer, the login to the computer and the activation of the ransomware is clearly visible in TeamViewer's logs.

It might be possible that hackers gain access by bruteforcing passwords, abusing zero-day vulnerabilities or by resetting passwords through email addresses obtained by other hacks. Whatever method they use, once they have access to the computer they upload a file to the desktop called surprise.exe. This is the actual ransomware which encrypts files and adds the extension .surprise.
A successful attempt looks like this in the TeamViewer logs:
03:00:27.983 1868 5664 S0 Estimated RTT to 479440875: 321 ms, Reliability: 3, Carrier: 2
03:02:35.931 4788 3996 G1 - File transfer request from -------- (xxx xxx xxx) allowed
03:02:36.400 4788 3996 G1 - Views folder <root drives>
03:02:37.603 4788 3996 G1 - Views folder <root drives>
03:02:41.666 4788 3996 G1 - Views folder C:\Users\MyUserName\Desktop\
03:02:48.932 4788 3996 G1 - Processing file transfer...
03:02:48.947 4788 3996 G1 - Write file C:\Users\MyUserName\Desktop\surprise.exe
03:02:51.197 4788 3996 G1 - File transfer finished.
03:02:51.197 4788 3996 G1 - Views folder C:\Users\MyUserName\Desktop\
03:02:53.010 4788 300 G1 Ending CFileTransferThreadServer...
03:02:53.010 4788 300 G1 The CFileTransferThreadServer has ended.
03:02:53.010 4788 3996 G1 - File transfer server shut down.
The ransomware is a variant of the open-source ransomware called EDA2 which was developed by a Turkish researcher. The cyber criminals simply make small changes to the EDA2 proof-of-concept of which the source code is readily available.
While the actual source of the issue isn't clear it's advisable to uninstall TeamViewer when not used. If you want to keep it, then make sure to upgrade to the latest version. When using unattended mode it's important to use a strong password.
Update: TeamViewer has reached out to us on Twitter:
@myce We have no security breach. We recommend adding another security layer by using a unique password and 2-factor authentication.
— TeamViewer Support (@TeamViewer_help) March 22, 2016















