Summary:
Researchers recently issued alerts to its customers regarding two instances of attempted ransomware attacks on separate endpoints. The threat actors gained initial access through TeamViewer; a legitimate remote access tool widely used in enterprises. The incidents bear similarities to the tactics discussed in a VMWare blog post, titled "LockBit 3.0 Ransomware Unlocked." The attackers deployed a ransomware payload, and while one endpoint was minimally impacted due to security software, the other experienced successful encryption. Huntress identified a common attacker through log analysis, highlighting the continued exploitation of TeamViewer for unauthorized access.[/subscribe_to_unlock_form]
Summary:
Researchers recently issued alerts to its customers regarding two instances of attempted ransomware attacks on separate endpoints. The threat actors gained initial access through TeamViewer; a legitimate remote access tool widely used in enterprises. The incidents bear similarities to the tactics discussed in a VMWare blog post, titled "LockBit 3.0 Ransomware Unlocked." The attackers deployed a ransomware payload, and while one endpoint was minimally impacted due to security software, the other experienced successful encryption. Huntress identified a common attacker through log analysis, highlighting the continued exploitation of TeamViewer for unauthorized access.[emaillocker id="1283"]
In both cases, the threat actors initiated the ransomware deployment using a DOS batch file named "PP.bat" from the user's desktop. The batch file executed a rundll32.exe command, launching a DLL file associated with the LockBit 3.0 ransomware. The first endpoint saw containment of the attack, limiting the impact to that specific system. However, on the second endpoint, the installed security software thwarted the initial attempts, forcing the threat actor to make repeated efforts to encrypt files. The analysis revealed specific log entries from TeamViewer connections, indicating repeated access by legitimate administrators on one endpoint and a lack of recent monitoring on the other, potentially making it a more attractive target.
The incidents underscore the importance of robust security measures, emphasizing the need for comprehensive asset inventories, including applications and vigilant monitoring of remote access tools like TeamViewer. The use of legitimate tools for malicious purposes, as seen in these attacks, poses a persistent threat. While Huntress couldn't definitively attribute the attacks to known ransomware gangs, the tactics resembled those associated with the leaked LockBit 3.0 ransomware builder. TeamViewer responded to the incidents, highlighting the significance of maintaining strong security practices, such as complex passwords, two-factor authentication, allow-lists, and regular software updates, to mitigate unauthorized access risks.
Threat Profile:

References:
The following reports contain further technical details:
[/emaillocker]