Skip to content

Malware

FINTEAM

aka TeamBot

Recently, Check Point researchers spotted a targeted attack against officials within government finance authorities and representatives in several embassies in Europe.

FINTEAM, also known as TeamBot, is a Windows malware family.

Background

Check Point researchers observed a targeted campaign aimed at officials in government finance bodies and at representatives across several European embassies. The intrusion begins with a malicious attachment masquerading as a top secret US document and abuses the widely used remote access and desktop sharing tool TeamViewer to seize full control of the victim's machine. This is accomplished by side-loading a rogue DLL alongside the legitimate TeamViewer binary.


Source: Malpedia (Fraunhofer FKIE).