Also known as: SIG39, TeamSpy, Team Bear, Anger Bear, IRON LYRIC, malicious actors, APT groups, hackers, tracked as, the Cozy Bear, Tech Sectors, OILRIG, Flying Kitten, Travnet, cpyy, APT3, Gothic Panda, UPS Team, DeputyDog, Parastoo, defense technology, military, diplomacy sectors, APT28, Pawn Storm, Fancy Bear, MiniDionis, Chinastrats, Agrius, HELIX KITTEN, TG-0110, Newscaster, Sednit, Hammertoss, Patchwork, SaffronRose, Saffron Rose, AjaxSecurityTeam, Ajax Security Team, Group 26, Sayad
**Targets:** This threat actor primarily compromises government entities and human rights activists in Eastern Europe and Central Asia for espionage purposes. It has also compromised private and public sector entities in the Middle East and in Western countries. **Toolset/Malware:** Malicious TeamViewer versions, JAVA RATs **Operations:** TeamSpy
Targeted Sectors
Targeted Countries / Regions
Executive Summary
TeamSpy Crew, also known as SIG39, is a nation-state threat actor primarily involved in espionage activities targeting government entities, human rights activists, and private sector organizations across Eastern Europe, Central Asia, and the Middle East. Their operations demonstrate significant technical sophistication, leveraging malicious TeamViewer versions and JAVA RATs to compromise systems for intelligence gathering.
Goals & Targeting
TeamSpy Crew's strategic objectives focus on intelligence gathering through espionage, particularly targeting sectors with significant geopolitical importance such as governments and human rights organizations. Their geographic scope in Eastern Europe, Central Asia, and the Middle East suggests a focus on regions with ongoing political or military tensions. The group's victims are often selected for their access to sensitive information that can be leveraged for broader geopolitical interests.
Enhanced Description
TeamSpy Crew is a nation-state actor known for its espionage activities targeting government entities, human rights activists, and private sector organizations in Eastern Europe, Central Asia, Middle East, and Western countries. Their primary toolset includes malicious TeamViewer versions and JAVA RATs, which enable them to gain unauthorized access to systems and establish persistence. The group's operations, often linked to geopolitical surveillance, highlight a strategic approach to targeting sensitive information from government agencies and high-value individuals.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
TeamSpy operations are characterized by targeted campaigns against government agencies and human rights activists. Notable tactics include spear phishing with malicious attachments and the deployment of remote access tools. Past activities have involved compromising systems in Eastern Europe and Central Asia, often linked to geopolitical interests.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in TeamSpy Crew's details is medium due to incomplete first and last seen data. IOC patterns are limited, but known TTPs provide a clear operational profile.
TeamSpy
No observed data linked yet.
1
Techniques
45
Tools
1
Campaigns
40
IOCs
0
Observed Data
1
Tactics