Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In a January 2024 investigation, Huntress found that ransomware deployment began after an actor accessed two separate endpoints through TeamViewer installations that were already present. The evidence shows TeamViewer as the observed entry path—not a proven TeamViewer software exploit, vulnerability, or misconfiguration. Huntress did not establish how the actor obtained the credentials used to access either endpoint.

What Huntress observed

Huntress SOC analysts investigated two unrelated endpoints where only a small number of ransomware canary files had been encrypted. In both cases, analysts correlated activity in TeamViewer’s connections_incoming.txt log with the start of the intrusion.

The ransomware files and activity looked similar to those associated with a leaked LockBit 3.0 builder. That was Huntress’ assessment of the artifacts, not confirmation that a LockBit operator conducted the attacks.

The incidents affected two endpoints. That is an incident count, not a measure of how common TeamViewer-based access is.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall

How the deployment unfolded

  1. The actor gained access through an existing TeamViewer installation using credentials that were accepted by the endpoint.

  2. Ransomware deployment began with a batch file launched from the user’s desktop.

  3. The batch file used rundll32.exe to invoke a DLL.

  4. On one endpoint, security software stopped the next stage. After the DLL was quarantined, the actor tried a different executable, which was also quarantined.

Huntress found no indication of reconnaissance beyond the affected endpoint or attempts to move laterally in either incident. That limited scope does not make the activity safe, and it does not mean endpoint security will always block a ransomware deployment.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What “used TeamViewer” does—and does not—mean

Observed access path

TeamViewer supplied the route into the endpoints because it was already installed and accepted the actor’s access. A legitimate remote-support tool can therefore be misused in the same way as any other valid remote-access channel.

Not evidence of a TeamViewer vulnerability

Huntress’ analysis did not indicate that the actor exploited a TeamViewer software vulnerability or a TeamViewer misconfiguration. The findings instead pointed to access through existing installations and known credentials.

Credential source remains unknown

Huntress did not determine whether the credentials came from an infostealer, keystroke logger, an initial-access broker, password reuse, or another route. Those possibilities were discussed as examples, not findings. The logs also do not prove password guessing, an insider, or a purchased foothold.

Why old remote-management installations matter

Remote-management software can remain on a device after a contractor, managed-service provider, or internal administrator changes. An installation that is no longer expected may still retain accounts, unattended-access settings, or allow-listed connections. Huntress therefore emphasizes maintaining accurate inventories of both systems and installed applications.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Review administrator workstations and other systems used to operate remote-management tools, not just the endpoints they connect to. Huntress noted limited visibility in some surrounding legitimate-access systems during its broader analysis; gaps there can make credential misuse harder to detect.

How to check TeamViewer for suspicious access

  1. Identify every endpoint and server where TeamViewer is installed, including devices managed by former or current service providers.

  2. On each relevant system, locate and preserve TeamViewer’s connections_incoming.txt log. The exact location and retention period can vary by TeamViewer version and configuration, so verify the details for your deployment before relying on a path or retention assumption.

  3. Compare incoming-connection timestamps, account names, source details, and session activity with approved maintenance windows and administrator records.

    Free tools Windows power users keep installed

    One-click scans. No signup required.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  4. Investigate entries that have no corresponding ticket, owner, or business purpose. Correlate them with process creation, file writes, endpoint alerts, and user reports rather than treating a log entry alone as proof of ransomware.

  5. Preserve the logs and endpoint evidence before changing settings if an intrusion is suspected; involve your incident-response team so containment does not destroy useful evidence.

Hardening remote access

In coverage published in January 2024, TeamViewer recommended complex passwords, two-factor authentication, allow-lists, current software versions, and disabling or restricting unused access. It also advised denying connections from outside the enterprise network where that fits the organization’s operating model. TeamViewer’s interface and policy names can change, so use its current documentation for exact configuration steps.

  • Remove what is not needed: Uninstall abandoned TeamViewer instances and revoke accounts or unattended-access permissions that no longer have an owner.
  • Require stronger authentication: Use unique, long credentials and multi-factor authentication where the current TeamViewer edition and deployment support it.
  • Constrain who can connect: Apply allow-lists and network restrictions that match approved administrators, vendors, devices, and locations.
  • Patch and monitor: Keep TeamViewer and the operating system current, and alert on unexpected incoming sessions or remote launches of scripting and execution tools.
  • Protect the operators: Monitor administrator workstations and other devices that store or use remote-access credentials.

How defenders should interpret the cases

Initial access is not the whole intrusion

The Huntress evidence supports an initial-access finding: TeamViewer sessions preceded the ransomware activity on the two endpoints. It does not establish persistence, command and control, or a broader campaign in these incidents.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Limited impact is not limited risk

Only a few canary files were encrypted, and one endpoint’s security software interrupted execution. Early blocking, an incomplete deployment, or an actor’s decision to stop can all produce limited damage while leaving credentials or access paths exposed.

Do not infer prevalence

No broad statistic in the incident report shows how often attackers enter organizations through TeamViewer. Two observed endpoints cannot support a rate or ranking of TeamViewer among ransomware access methods.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

If you find an unexplained TeamViewer session

  1. Disconnect or isolate the affected endpoint according to your incident-response plan, while avoiding unnecessary destruction of volatile evidence.

  2. Preserve TeamViewer logs, endpoint-detection alerts, the batch file, the invoked DLL or executable, and relevant authentication records.

    What’s actually slowing this PC down?

    Pick the symptom - the matching free tool is one click away.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  3. Disable or rotate the suspected TeamViewer credentials and review the same credentials anywhere else they were reused.

  4. Search other managed endpoints and administrator workstations for matching sessions, files, hashes, or execution timestamps.

  5. Assess whether any data, accounts, or additional systems were accessed before restoring normal remote-management service.

Frequently Asked Questions

Can attackers use TeamViewer to get into a business computer?

Yes. These Huntress cases show that an attacker can use an already-installed TeamViewer instance when valid access credentials are available. The cases did not show that TeamViewer itself was exploited, and they did not identify how the credentials were obtained.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How common is ransomware access through TeamViewer?

The report covers two endpoints and does not provide a prevalence rate. It should be treated as a documented access pattern, not evidence of how frequently ransomware actors use TeamViewer.

The Bottom Line

Huntress documented TeamViewer as the initial access route in two ransomware incidents because existing installations accepted the actor’s credentials. Inventory every remote-management installation, review incoming-connection history, remove abandoned access, enforce strong authentication and network restrictions, and investigate the credential-compromise question separately from the access path.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.