APT29 Targeting Zimbra and TeamCity Servers (Campaign)
ID: 047216f3-7a62-587f-a351-173b5ee473b8
STIX ID: report--047216f3-7a62-587f-a351-173b5ee473b8
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2024-10-10
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
US and UK cyber agencies warn that SVR-linked APT29 (Cozy Bear) is actively exploiting a Zimbra command-injection vulnerability (CVE-2022-27924) and a TeamCity authentication bypass (CVE-2023-42793) to steal credentials, compromise email and build servers, and enable ransomware and supply-chain attacks; the actors use phishing, password spraying, TOR/proxies, and pre-compromised/cloud-misconfigured assets to obfuscate activity and move laterally.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
