---
title: "Ransomware Deployment Attempts Via TeamViewer"
url: https://daily.dev/posts/ransomware-deployment-attempts-via-teamviewer-wijj1xwza
source_url: https://www.huntress.com/blog/ransomware-deployment-attempts-via-teamviewer
type: article
source: "Huntress Blog"
published: 2026-05-31T07:43:28.334Z
updated: 2026-05-31T08:57:02.575Z
tags: ["ransomware", "lockbit"]
reading_time: 3
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Ransomware Deployment Attempts Via TeamViewer

**[Huntress Blog](https://daily.dev/sources/huntress-blog)** · 3 min read · 0 upvotes · 0 comments

## Summary

Huntress SOC analysts investigated two endpoints minimally impacted by ransomware, where initial access was gained through TeamViewer remote connections. Log analysis from TeamViewer's connections_incoming.txt revealed both endpoints were accessed from the same source machine (WIN-8GPEJ3VGB8U) on December 21, 2023. The threat actor deployed a DOS batch file that executed a LockBit 3.0 DLL via rundll32.exe. On one endpoint, installed security software quarantined the ransomware files before significant damage occurred. The incident highlights the risk of legacy or poorly managed TeamViewer installations and the importance of maintaining a complete application inventory as part of basic security hygiene. IOCs including the attacker's endpoint name and DLL SHA256 hash are provided.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.huntress.com/blog/ransomware-deployment-attempts-via-teamviewer>

## Similar posts on daily.dev

- [Ransomware Attack Vectors: 5 Endpoint Blind Spots](https://daily.dev/posts/ransomware-attack-vectors-5-endpoint-blind-spots-plmyjumdm) · Cyble · 0 upvotes · 0 comments

---

Tags: [#ransomware](https://daily.dev/tags/ransomware), [#lockbit](https://daily.dev/tags/lockbit)

[View this post on daily.dev](https://daily.dev/posts/ransomware-deployment-attempts-via-teamviewer-wijj1xwza)
