The JetBrains TeamCity software supply chain attack: Lessons learned
ID: 7931a6a9-fdb1-5d00-b416-3f377eaa0088
STIX ID: report--7931a6a9-fdb1-5d00-b416-3f377eaa0088
Feed Name: ReversingLabs Blog
Date Published: 2023-12-21
Date Updated: 2026-04-29
Author: [email protected] (John P. Mello Jr.)
**Executive summary:** SVR-linked actors associated with the SunBurst campaign are actively exploiting a known TeamCity vulnerability (CVE-2023-42793) to compromise CI/CD servers, deploy the GraphicalProton backdoor, and leverage tools such as Mimikatz and DLL hijacking (via Zabbix) to escalate privileges and persist, creating significant software supply-chain risk; CISA has alerted organizations but patch uptake remains low, so teams should prioritize patching, binary analysis of builds, and stronger AppSec practices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
