Russia joins North Korea in sending state-sponsored cyber troops to pick on TeamCity users
ID: e122b631-767a-5ff5-858f-b39227691b3d
STIX ID: report--e122b631-767a-5ff5-858f-b39227691b3d
Feed Name: The Register (Security)
Multiple Western and Polish cyber agencies warn that an SVR-linked offensive unit has been exploiting a critical TeamCity vulnerability (CVE-2023-42793, CVSS 9.8) at scale since September; attackers deployed the GraphicalProton backdoor (with layered obfuscation), used DLL hijacking via legitimate open-source tools (Zabbix, vcperf), abused cloud services (Dropbox/OneDrive) for C2, performed credential theft and lateral movement (Mimikatz, AD enumeration), and planted persistent backdoors — telemetry shows hundreds of vulnerable TeamCity instances remain and the advisory includes IOCs and mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
