logo

Russia joins North Korea in sending state-sponsored cyber troops to pick on TeamCity users

ID: e122b631-767a-5ff5-858f-b39227691b3d

STIX ID: report--e122b631-767a-5ff5-858f-b39227691b3d

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2023-12-14

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Multiple Western and Polish cyber agencies warn that an SVR-linked offensive unit has been exploiting a critical TeamCity vulnerability (CVE-2023-42793, CVSS 9.8) at scale since September; attackers deployed the GraphicalProton backdoor (with layered obfuscation), used DLL hijacking via legitimate open-source tools (Zabbix, vcperf), abused cloud services (Dropbox/OneDrive) for C2, performed credential theft and lateral movement (Mimikatz, AD enumeration), and planted persistent backdoors — telemetry shows hundreds of vulnerable TeamCity instances remain and the advisory includes IOCs and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.