{"id":11998,"date":"2024-07-01T10:47:20","date_gmt":"2024-06-30T22:47:20","guid":{"rendered":"https:\/\/kinetics.co.nz\/?p=11998"},"modified":"2024-07-01T10:47:20","modified_gmt":"2024-06-30T22:47:20","slug":"teamviewer-compromise","status":"publish","type":"post","link":"https:\/\/new.kinetics.co.nz\/?p=11998","title":{"rendered":"TeamViewer Compromise"},"content":{"rendered":"<p>[et_pb_section fb_built=&#8221;1&#8243; _builder_version=&#8221;4.24.3&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_row column_structure=&#8221;1_2,1_2&#8243; _builder_version=&#8221;4.24.3&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column type=&#8221;1_2&#8243; _builder_version=&#8221;4.24.3&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.24.3&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<\/p>\n<p>TeamViewer is a common piece for software that allows IT businesses to remotely access, control, manage, monitor, and repair devices \u2013 from laptops and mobile phones to industrial machines and robots. Many software vendors include it to allow them to remotely support their software for their clients.<\/p>\n<p>[\/et_pb_text][\/et_pb_column][et_pb_column type=&#8221;1_2&#8243; _builder_version=&#8221;4.24.3&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_image src=&#8221;\/wp-content\/uploads\/2024\/07\/TeamViewer.png&#8221; title_text=&#8221;TeamViewer&#8221; _builder_version=&#8221;4.24.3&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][\/et_pb_image][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=&#8221;4.24.3&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.24.3&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.24.3&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<\/p>\n<h2>Word is coming out quickly that TeamViewer has found an &#8220;irregularity&#8221; on their internal networks yesterday.<\/h2>\n<p><a href=\"https:\/\/www.teamviewer.com\/en\/resources\/trust-center\/statement\/\">https:\/\/www.teamviewer.com\/en\/resources\/trust-center\/statement\/<\/a><\/p>\n<p>Their claim is that their product remains safe, however, Trend Micro has been tracking unusual connections, including from TeamViewer instances protected by strong passwords and MFA, for at least a month. This story is developing quickly and we are watching it closely.<\/p>\n<p><a href=\"https:\/\/www.trendmicro.com\/vinfo\/nz\/security\/news\/cyber-attacks\/hack-on-teamviewer-after-reported-unauthorized-connections\">https:\/\/www.trendmicro.com\/vinfo\/nz\/security\/news\/cyber-attacks\/hack-on-teamviewer-after-reported-unauthorized-connections<\/a><\/p>\n<h3>Please note that TeamViewer is not in the Kinetics KARE Tech stack.<\/h3>\n<p>We don\u2019t install it as part of our support platform, BUT it is included by some software vendors for their technical support of their customers. We are working through a list of all clients to make sure protections are in place.<\/p>\n<p>This attack is suspected to have come from the APT29 group. This is a group associated with Russian Foreign Intelligence Service and has been able to breach Microsoft in recent history.\u00a0<a href=\"https:\/\/attack.mitre.org\/groups\/G0016\/\">https:\/\/attack.mitre.org\/groups\/G0016\/<\/a><\/p>\n<p>It shows even large security focused companies are vulnerable to the basics, as well as the need to reduce exposure and only use\/install these very powerful tools when there is a clear need for them.<\/p>\n<p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.24.3&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<\/p>\n<h3>Update: 11:00am 1 July 2024<\/h3>\n<p>A few hours ago, Teamviewer have released further information that looks like the immediate risk to other systems is low at this stage.\u00a0 They say that\u00a0<em>&#8220;the threat actor leveraged a compromised employee account&#8221;<\/em><\/p>\n<p>\u00a0<span>The compromised systems:\u00a0<\/span><em>&#8220;copy employee directory data, i.e. names, corporate contact information, and encrypted employee passwords&#8221;<\/em><\/p>\n<p><span>This sounds like they got into Teamviewers AD, this is pretty bad, and means the ongoing risk for them and their customers is certainly non-zero<\/span><\/p>\n<p>\u00a0<strong>The remediation actions they are taking are:\u00a0<\/strong><em>&#8220;We hardened authentication procedures for our employees to a maximum level and implemented further strong protection layers. Additionally, we have started to rebuild the internal corporate IT environment towards a fully trusted state.&#8221;<\/em><\/p>\n<p>We think t<span>his is the right path, and a major undertaking for them. It gives us confidence that, at this time, there is no need at this time, for any drastic action by clients using this software.\u00a0\u00a0<\/span><\/p>\n<p>Our advice is\u00a0 that if Teamviewer is required, or is part of a managed product, like OneLaw, then its fine to leave it installed.\u00a0 Otherwise, if it is not required, it shouldn&#8217;t be installed. Where it is installed, MFA and strong authentication should be enforced.<\/p>\n<p>In fact, learning from this, we bet TeamViewer wish they had enforced MFA onm all their users.\u00a0 <strong>EVERYONE NEEDS MFA ON EVERYTHING<\/strong><\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>TeamViewer is a common piece for software that allows IT businesses to remotely access, control, manage, monitor, and repair devices \u2013 from laptops and mobile phones to industrial machines and robots. Many software vendors include it to allow them to remotely support their software for their clients.Word is coming out quickly that TeamViewer has found [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":11999,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"on","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[4,5],"tags":[],"class_list":["post-11998","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","category-security"],"_links":{"self":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts\/11998","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=11998"}],"version-history":[{"count":0,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts\/11998\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/"}],"wp:attachment":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=11998"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=11998"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=11998"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}