Uptime Hamster: 10d 12h 50mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza TeamSpy Crew

TeamSpy Crew

0 incidentes 0 paises 0 sectores apt RU Ultimo: -
Aliases: Team Bear, IRON LYRIC, TeamSpy, Anger Bear, SIG39, Malicious TeamViewer versions, JAVA RATs
Ver en IntelTracker → APTTrail →
TeamSpy Crew is a cyber-espionage group known for long-running covert surveillance and data theft operations primarily against governmental organizations, private companies, and human rights activists. While their activity using self-made malware tools dates back to at least 2004, the group gained notoriety for their distinct method of abusing legitimate TeamViewer remote administration software, a practice observed since 2012. Their main objective is intelligence gathering rather than financial gain through typical extortion methods. A defining characteristic of TeamSpy Crew is their unique tactic of dynamically patching TeamViewer in memory, often employing DLL hijacking, to maintain stealthy, persistent access and bypass detection. The group is also identified by aliases such as Team Bear, IRON LYRIC, TeamSpy, Anger Bear, and IG39, which reflect varied naming across different investigations rather than distinct operational units.

Aliases del actor

Team BearIRON LYRICTeamSpyAnger BearSIG39Malicious TeamViewer versionsJAVA RATs

Actores similares

teamspy-crewactor · 1APT29 (Cozy Bear)actor · 1Saint Bearactor · 1energetic-bearactor · 1ember-bearactor · 1Energetic Bearapt · 0Boulder Bearapt · 0Pat Bearapt · 0White Bearapt · 0spacebearsransomware · 31
Motivacion