A group that threatens actors brings back to the surface the malicious software TVSPY, which exploits a vulnerability in Teamviewer in the 6th version of the software, a legitimate tool used for remote computer management. This time however, the attackers packaged Teamviewer V6 together with a copy of the malicious software.

“This particular threat is very dangerous, as the attacker will have full control over the infected machine,” said the researchers at Damballa, who discovered the threat. “It can be used during a common infection campaign or by certain APT actors for specific attacks against specific targets.”
More recently, a targeted email campaign included a malicious Excel file with a macro that downloads the malware. The email impersonates the All-Russian Research and Design Institute of Nuclear Energy and Engineering, and analysis of the Command and Control server for this latest variant appears to be from professional criminals.
Damballa notes that the number of unique variants it has seen in 2015 is 4.4 times the number it had seen in 2012, and 2.2 times the number observed in all of 2014. There are some cases where Dridex also installs this malware.
“This malware has been relatively quiet for more than two years, so the almost threefold increase in its activity is concerning,” according to the researchers.
TVSPY, also known as TVRAT, spy-Agent, or teamspy, was originally developed in 2010 by a hacker who followed in Mr. Burns’ footsteps. He also created something similar called RMS, which behaves very much like the creator of TVSPY.
“RMS/TVSPY continues to be developed, with a new version published by the creator/reseller of the project, on a regular basis,” Damballa researchers note. “In fact, the legitimate version of RMS was developed by TektonIT, and the version posted on criminal forums appears to be identical. TVSPY appears to be simply a modification of RMS to use the TeamViewer infrastructure and a command-and-control interface manageable via the Web.”
