TerraTV is a Golden Chickens malware module associated with the financially motivated threat ecosystem also tracked as Venom Spider and used by operators including Evilnum. It is designed to hijack a victim organization’s TeamViewer installation so attackers can use the legitimate remote-access application on compromised machines. Reported behavior includes placing a malicious DLL in the TeamViewer application directory so the legitimate TeamViewer process loads attacker-controlled code instead of the expected system library, enabling TeamViewer hijacking through DLL search-order abuse. This capability supports post-compromise operations by blending attacker activity with legitimate remote administration software.
TerraTV is primarily used after initial compromise as part of a broader modular intrusion set that also includes components such as VenomLNK, TerraLoader, TerraStealer, TerraPreter, and TerraCrypt. In observed operations, Evilnum used TerraTV to run legitimate TeamViewer on infected hosts and connect to those systems remotely. Its main operational purpose is lateral movement and remote access within victim environments rather than standalone initial infection. Activity linked to TerraTV has been associated with targeted financially motivated intrusions, including campaigns against FinTech organizations in the UK and Europe. The malware’s use of legitimate software and DLL sideloading techniques also contributes to defense evasion by making malicious activity resemble normal administrative behavior.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Evilnum has used the malware variant, TerraTV, to load a malicious DLL placed in the TeamViewer directory, instead of the original Windows DLL located in a system folder.
These modules include TerraStealer for credential harvesting, TerraTV for TeamViewer hijacking, and TerraCrypt for ransomware deployment.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
"Related Families: VenomLNK, TerraLoader, TerraStealer, TerraTV, TerraCrypt, TerraRecon, TerraWiper, lite_more_eggs, RevC2, Venom Loader"
Golden Chickens module used for TeamViewer hijacking to facilitate remote access/control.
A named malware/tool in the Golden Chickens ecosystem that the content states was used by Evilnum.
A malware tool from the Golden Chickens ecosystem mentioned as used by Evilnum.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.