logo

Russian Foreign Intelligence Service (SVR) Exploiting JetBrains TeamCity CVE Globally

ID: 9487cd19-8462-5e76-ace9-651c272e2d27

STIX ID: report--9487cd19-8462-5e76-ace9-651c272e2d27

Feed Name: CISA Cybersecurity Advisories

Threat Score
90/100

Date Published: 2023-12-12

Date Updated: 2026-04-19

Author: CISA

...
...

### Executive summary A joint advisory from multiple national CERTs and agencies attributes an active campaign to the Russian SVR (APT29) exploiting CVE-2023-42793 in unpatched JetBrains TeamCity servers since September 2023 to gain high-privilege code execution, deploy GraphicalProton backdoors (HTTP/OneDrive/Dropbox variants), bypass EDR/AV using EDRSandBlast and vulnerable drivers, exfiltrate sensitive files and registry hives, and establish persistent access; the report includes IOCs, detection rules (Sigma/YARA), MITRE ATT&CK mappings, and mitigation recommendations such as patching TeamCity, assuming compromise if unpatched, and initiating threat hunting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.