Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors TeamSpy Crew

Also known as: SIG39, TeamSpy, Team Bear, Anger Bear, IRON LYRIC, malicious actors, APT groups, hackers, tracked as, the Cozy Bear, Tech Sectors, OILRIG, Flying Kitten, Travnet, cpyy, APT3, Gothic Panda, UPS Team, DeputyDog, Parastoo, defense technology, military, diplomacy sectors, APT28, Pawn Storm, Fancy Bear, MiniDionis, Chinastrats, Agrius, HELIX KITTEN, TG-0110, Newscaster, Sednit, Hammertoss, Patchwork, SaffronRose, Saffron Rose, AjaxSecurityTeam, Ajax Security Team, Group 26, Sayad

Description

**Targets:** This threat actor primarily compromises government entities and human rights activists in Eastern Europe and Central Asia for espionage purposes. It has also compromised private and public sector entities in the Middle East and in Western countries. **Toolset/Malware:** Malicious TeamViewer versions, JAVA RATs **Operations:** TeamSpy

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Non profit
Energy
Telecommunications
Aerospace
Media
Education
Maritime
Manufacturing
Healthcare
Critical infrastructure
Think tank
Information technology
Utilities
Hospitality
Pharmaceutical
Oil gas
Chemical
Gaming
Retail
Transportation
Mining
Legal services
Nuclear
Entertainment

Targeted Countries / Regions

middle_east
europe
central_asia
US
CN
RU
IN
JP
GB
KR
DE
IR
SA
TW
UA
IL
PK
KZ
VN
FR
BY
CA
TR
PL
AU
KP
AE
MX
IT
SY
SG
NL
BR
ES
IQ
RO
LB
EG
AZ

AI Analysis

· 1 week ago

Executive Summary

TeamSpy Crew, also known as SIG39, is a nation-state threat actor primarily involved in espionage activities targeting government entities, human rights activists, and private sector organizations across Eastern Europe, Central Asia, and the Middle East. Their operations demonstrate significant technical sophistication, leveraging malicious TeamViewer versions and JAVA RATs to compromise systems for intelligence gathering.

Goals & Targeting

TeamSpy Crew's strategic objectives focus on intelligence gathering through espionage, particularly targeting sectors with significant geopolitical importance such as governments and human rights organizations. Their geographic scope in Eastern Europe, Central Asia, and the Middle East suggests a focus on regions with ongoing political or military tensions. The group's victims are often selected for their access to sensitive information that can be leveraged for broader geopolitical interests.

Enhanced Description

TeamSpy Crew is a nation-state actor known for its espionage activities targeting government entities, human rights activists, and private sector organizations in Eastern Europe, Central Asia, Middle East, and Western countries. Their primary toolset includes malicious TeamViewer versions and JAVA RATs, which enable them to gain unauthorized access to systems and establish persistence. The group's operations, often linked to geopolitical surveillance, highlight a strategic approach to targeting sensitive information from government agencies and high-value individuals.

Key Capabilities

  • Use of malicious TeamViewer versions
  • Deployment of JAVA RATs
  • Social engineering tactics
  • Persistent remote access
  • Data exfiltration techniques

MITRE ATT&CK Tactics

Spear Phishing
Malware
Initial Access
Execution
Lateral Movement

ATT&CK Techniques

T1059.003
T1078
T1566.001
T1003

Software / Tooling

TeamViewer
JAVA RATs
Cobalt Strike

Campaigns & Victims

TeamSpy operations are characterized by targeted campaigns against government agencies and human rights activists. Notable tactics include spear phishing with malicious attachments and the deployment of remote access tools. Past activities have involved compromising systems in Eastern Europe and Central Asia, often linked to geopolitical interests.

IOC Patterns

  • Spear-phishing emails with malicious TeamViewer links
  • Network traffic with C2 communication using legitimate protocols
  • Presence of JAVA RATs on compromised systems

Recommended Actions

  • Implement robust phishing detection solutions
  • Monitor network traffic for异常通讯迹象
  • Regularly update software to patch vulnerabilities
  • Conduct employee training on social engineering tactics

Suggested Tags

APT
espionage
government
nation-state
CISA
intelligence

Confidence Assessment

Confidence in TeamSpy Crew's details is medium due to incomplete first and last seen data. IOC patterns are limited, but known TTPs provide a clear operational profile.

ATT&CK Techniques

1 technique

Software / Tooling

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

Filename 4 MD5 Hash 5 Domain 11

References

  1. github.com — Cited by web research for: Tech Sectors
  2. misp-galaxy.org — Cited by web research for: cpyy
  3. ics-cert.kaspersky.com — Cited by web research for: phishing
  4. securelist.com — Cited by web research for: Dark

Intel Summary

1

Techniques

45

Tools

1

Campaigns

40

IOCs

0

Observed Data

1

Tactics

Tags

APT
espionage
government
nation-state
CISA
intelligence

Details

Type
Nation-State
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
Russia (RU)
Confidence
70%
Added
Jul 21, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.