Tuesday, April 22, 2025
HomeCyber Security NewsRussian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

Published on

SIEM as a Service

Follow Us on Google News

TeamViewer’s popularity and remote access capabilities make it an attractive target for those seeking to compromise systems for their gain.

Threat actors target TeamViewer for their illicit purposes because it is a widely used remote desktop software with potential security weaknesses. 

Exploiting vulnerabilities in TeamViewer can provide unauthorized access to systems and sensitive data, enabling cybercriminals to carry out various malicious activities, such as data theft, financial fraud, or even using compromised systems to launch attacks on other targets.

- Advertisement - Google News

In late 2022, QiAnXin Threat Intelligence Center identified a new threat actor group using fake software download sites with manipulated search rankings to distribute unofficial but seemingly valid installation packages created with Inno Setup.

Russian Hackers Bypass EDR

Attribution was challenging due to the attackers’ complex attack chain and manual operations. 

In mid-2023, TeamViewer’s DLL Sideloading was delivered via SFTP, hinting at a connection to the attacks on security researchers in 2021.

Phishing activity timeline
Phishing activity timeline (Source – Qianxin)

The execution chain focuses on SSH reverse tunnels, leveraging OpenSSH to bypass EDR endpoint detection. 

Attackers employed sftp-server.exe to deliver the TeamViewer hijacking component, revealing the use of MINEBRIDGE RAT. 

AnyDesk and PsExec were also used for lateral propagation, with data decryption occurring within the victim’s user context.

Attack chain
Attack chain (Source – Qianxin)

In total, four legitimate signatures were used in this phishing operation, some still valid in the report, with an enigmatic use of Amadey Trojan.

  • GUTON LLC: FC2BDF5BD23470669F63B9A5BAE6305160DCBC67
  • NTB CONSULTING SERVICES INC: A05536924F1BA8F99BA6B1AA3C97B809E32A477E
  • OOO RIMMA: A1C753F5271F24B8067AC864BB4192C37265840C
  • KATEN LLC: 9A865A28A85CABC3F79C88BE54AF3B20962BC35C

Researchers uncovered a new MINEBRIDGE RAT variant with LLVM obfuscation, removing old C&C instructions. 

The sample retrieves a DLL from the server to execute PowerShell commands for SSH component download, consistent with previous scripts.

Attribution

The group has been active since 2021 based on domain registration times. They used Cloudflare CDN to obscure their IP, but few OSINT reports on MINEBRIDGE made tracking challenging.

QiAnXin’s data shows that the malicious domains communicated with both corporate dedicated lines and home broadband in mainland China during their Cloudflare CDN phase.

The enterprises involved were in the following sectors:-

  • Cryptocurrency
  • Electronic components
  • Technology
  • Investment
  • Healthcare

Recent findings suggest Storm-0978 (RomCom), TA505, and MINEBRIDGE have strong connections, possibly indicating shared activities beyond economic motivations.

Protect yourself from vulnerabilities using Patch Manager Plus to patch over 850 third-party applications quickly. Take advantage of the free trial to ensure 100% security.

Tushar Subhra
Tushar Subhra
Tushar is a Cyber security content editor with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news.

Latest articles

Hackers Exploit Legitimate Microsoft Utility to Deliver Malicious DLL Payload

Hackers are now exploiting a legitimate Microsoft utility, mavinject.exe, to inject malicious DLLs into...

Cybercriminals Exploit Network Edge Devices to Infiltrate SMBs

Small and midsized businesses (SMBs) continue to be prime targets for cybercriminals, with network...

Criminal IP to Showcase Advanced Threat Intelligence at RSAC™ 2025

Joining Criminal IP at Booth S-634 | South Expo, Moscone Center | April 28...

TP-Link Router Vulnerabilities Allow Attackers to Execute Malicious SQL Commands

Cybersecurity researchers have uncovered critical SQL injection vulnerabilities in four TP-Link router models, enabling...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Hackers Exploit Legitimate Microsoft Utility to Deliver Malicious DLL Payload

Hackers are now exploiting a legitimate Microsoft utility, mavinject.exe, to inject malicious DLLs into...

Cybercriminals Exploit Network Edge Devices to Infiltrate SMBs

Small and midsized businesses (SMBs) continue to be prime targets for cybercriminals, with network...

TP-Link Router Vulnerabilities Allow Attackers to Execute Malicious SQL Commands

Cybersecurity researchers have uncovered critical SQL injection vulnerabilities in four TP-Link router models, enabling...