TeamViewer is a tool tracked across 16 threat clusters and 14 intelligence report mentions on ThreatCluster. First observed November 3, 2025; most recent activity May 28, 2026.
TeamViewer is a legitimate remote-access and support platform widely used for IT administration and troubleshooting. In threat intelligence, remote-control capabilities like those offered by TeamViewer are frequently abused by spyware operators and fraudsters to access victim systems and conduct surveillance, underscoring the security risks associated with widely-used remote-access tools.
In March 2026, the Trigona ransomware group, which operates as a Ransomware-as-a-Service (RaaS), utilized a newly developed custom tool named 'uploader_client.exe' to enhance their data exfiltration capabilities. This…
The Union Ministry of Affairs (MHA) has issued warnings regarding a surge in cyber scams targeting job seekers and online shoppers. The National Cybercrime Threat Analytics Unit (NCTAU) reported that fraudsters are…
As of February 12, 2026, organizations worldwide are experiencing an average of 2,090 cyber-attacks per week, largely driven by ransomware incidents. This increase highlights the ongoing challenges faced by businesses…
DragonForce, a new ransomware operation derived from Conti's leaked source code, has emerged with a cartel-like structure. The group retains Conti's core encryption and network-spreading capabilities while recruiting…
A study by Semperis reveals that 52% of ransomware attacks target organizations during holidays and weekends, exploiting reduced cybersecurity staffing. The report surveyed 1,500 IT and security professionals across ten…
The Acronis H2 2025 Cyberthreats Report indicates a significant increase in cyberattacks, with email-based attacks rising 16% per organization and 20% per user year-over-year. Phishing remains the primary entry point…
In 2025, ransomware groups Medusa and DragonForce targeted UK organizations by exploiting three critical vulnerabilities in the SimpleHelp Remote Monitoring and Management platform. These vulnerabilities…
The Crazy ransomware gang has been observed exploiting legitimate employee monitoring software, specifically Net Monitor for Employees Professional, along with the SimpleHelp remote support tool. This tactic allows them…
Canadian cybersecurity officials reported a series of attacks by hacktivists on critical infrastructure, specifically targeting industrial control systems (ICS) in water, energy, and agricultural sectors. The Canadian…
Intellexa, a spyware maker known for its Predator software, has been found to have remote access to the surveillance systems of its government clients, allowing staff to view personal data of hacked individuals. Despite…