According to security firm Heimdal, a new spam campaign appeared over the weekend carrying TeamSpy malware, a malware that can give hackers full access to a computer via Teamviewer.
TeamSpy is not a new type of malware. In fact, it has been around since 2013, and by then it had gained access to countless computers.
This time the attackers use social engineering techniques and, taking advantage of the carelessness of users, trick them into installing the TeamSpy malware.
How it works:
The malware comes as a .zip file in an email from a spoofed address. The zip contains an .exe file that, if run, will infect your computer with TeamSpy, a malicious DLL file. The emails containing the malware, according to the company that discovered them, had the subject line “eFax message from “1408581 **.”
The malware will install a legitimate version of TeamViewer on its victims' computers and then change the behavior of the hacked DLL to remain hidden.
"The TeamSpy malware includes several components from the legitimate TeamViewer application. A keylogger and TeamViewer VPN are two of these components," Heimdal researchers report.
All logs are copied to a file. This includes all available usernames and passwords. The file is then sent to a C&C server.
This particular attack can bypass two-factor authentication. Currently, the malware's detection rate is very low (15/58), which means that only 15 antivirus software is able to detect it.
This can be explained by the fact that it is the beginning of the attack. So it would be a good idea to be careful about the emails you receive and not download files that do not seem trustworthy.
