TeamSpy Crew is a cyber-espionage group known for long-running covert surveillance and data theft operations primarily against governmental organizations, private companies, and human rights activists. While their activity using self-made malware tools dates back to at least 2004, the group gained notoriety for their distinct method of abusing legitimate TeamViewer remote administration software, a practice observed since 2012. Their main objective is intelligence gathering rather than financial gain through typical extortion methods. A defining characteristic of TeamSpy Crew is their unique tactic of dynamically patching TeamViewer in memory, often employing DLL hijacking, to maintain stealthy, persistent access and bypass detection. The group is also identified by aliases such as Team Bear, IRON LYRIC, TeamSpy, Anger Bear, and IG39, which reflect varied naming across different investigations rather than distinct operational units.