logo

BianLian Threat Actors Exploiting JetBrains TeamCity Flaws in Ransomware Attacks

ID: 3c63d957-0a64-5fbd-a509-e4921664002a

STIX ID: report--3c63d957-0a64-5fbd-a509-e4921664002a

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-03-11

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

GuidePoint Security and other researchers observed BianLian ransomware actors exploiting critical TeamCity vulnerabilities (CVE-2024-27198 or CVE-2023-42793) to gain initial access, create accounts, and deploy a PowerShell implementation of their Go backdoor (BianDoor) for exfiltration-based extortion; the report highlights living-off-the-land techniques, use of remote access tools, and notes related active exploitation of Confluence CVE-2023-22527 by other ransomware families.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.