Skip to main content

Remote access software TeamViewer has been spying on us for decades

teamviewerSince its introduction, TeamViewer has been looked upon with some suspicion by the more paranoid Internet users out there. After all,if the software exists with the primary purpose of allowing group meetings with remote access to other people’s computers from anywhere in the world, what’s to say that someone else couldn’t use it for some downright evil mischief?

Now, there’s evidence to suggest that such skepticism was well-founded. A blog post from the Laboratory of Cryptography and System Security in Budapest, Hungary, claims it has uncovered “an ongoing high profile targeted attack affecting our home country” that appears to center around misuse of TeamViewer software.

“A distinct feature of the attack is the abuse of the legitimate TeamViewer remote access tool,” the blog writes. It appears that infected computers originally had “clean” versions of the TeamViewer software installed before they were modified afterward, allowing third parties to gain remote access to machines without their users’ knowledge. This means hackers would be able not only to observe (and record) keystrokes used by the legitimate users, but could also install further malware on the machines without detection.

“The collected evidence suggest[s] that attacks have been carried out in multiple campaigns,” the post continues, suggesting that the malware attacks predate the use of TeamViewer. The CrySyS lab traced attacks to as far back as 2010 definitively, but believes that hackers have started earlier, estimating a number in double digits in terms of how many have been carried out.

Nonetheless, the group believes that those behind the TeamViewer abuse have also been behind other similar attacks, noting that the “TeamBot/Sheldor campaign” – a cyber campaign against financial institutions – may have its roots in the same source.

It’s not just Hungary that finds itself faced with this problem, either. “The telemetry revealed additional high-profile victims outside Hungary,” the blog post notes. “Indeed, multiple victims were found in Iran, including victims at http://www.sashiraz.co.ir, which is an electronics company with government background.” Other international victims of the attacks include multiple research and educational groups in France and Belgium, an electronics manufacturer with government connections in the Middle East and a NATO state embassy in Russia. Additionally, an industrial manufacturer in Russia has also been compromised.

At this time, it remains unknown where the attacks originated from. Some tools used in the attacks ran to an unknown host on a subnet. Interestingly enough, the CrySyS lab team has also tracked other tools to hosts belonging to the Ministry of Foreign Affairs of Uzbekistan. But the most obvious question remains: Why Hungary, of all places?

Graeme McMillan
Former Digital Trends Contributor
A transplant from the west coast of Scotland to the west coast of America, Graeme is a freelance writer with a taste for pop…
How to enable picture-in-picture for YouTube on your Mac
Macbook Air

If you want to have a bit of music playing in the background or want to have your favorite YouTube video running in the corner of your screen, then the picture-in-picture YouTube feature needs to be on your radar. This allows you to turn your YouTube videos into a tiny pop-up window that can be moved and repositioned around your screen.

Mac users have several ways to activate the feature, including support on both Safari and Google Chrome. There's also a nifty Chrome extension that simplifies the task to a single button press. Here's a look at how to enable picture-in-picture for YouTube on your Mac.

Read more
How to change your Gmail password
pilot testing drivers licenses internet rolls two us states password

Changing your Gmail password is incredibly important for your online security. If you're anything like the average user, your Gmail account is linked to dozens of other organizations and programs – and if your account gets hacked, there's no telling what sort of damage can be done.

Because of this, it's crucial to change your Gmail password at regular intervals. Google makes this a rather painless process, and it should take no more than a few seconds from start to finish.

Read more
Best Buy deals: Save on laptops, TVs, appliances, and more
best buy shuts down insignia line smart home products store 2 768x768

Best Buy is always a great retailer to turn to if you’re looking for some savings. There are almost always Best Buy deals taking place on TVs, appliances, and devices we use to navigate the digital world. In fact, right now at Best Buy you can find some of the best TV deals, best laptop deals, and best phone deals that can be shopped, and we haven’t even mentioned the deals on tablets and home audio equipment currently taking place at Best Buy. We’ve rounded up all of the best Best Buy deals you can shop right now and categorized them for your convenience below, so read onward for some great opportunities to save.
Best Buy TV deals

There may be no better place to purchase one of the best TVs than Best Buy. There is almost always some huge savings to find on TVs at Best Buy, and that’s certainly the case right now. You’ll find deals top TV brands like Sony, Samsung, and LG, and more budget-friendly brands like TCL and Hisense are in play, too.

Read more