TeamCity Flaw Leads to Surge in Ransomware, Cryptomining, and RAT Attacks
ID: e224b513-8c04-5b6e-b73f-097d3a211ce1
STIX ID: report--e224b513-8c04-5b6e-b73f-097d3a211ce1
Feed Name: The Hacker News
Multiple threat actors are actively exploiting the critical JetBrains TeamCity vulnerability (CVE-2024-27198, CVSS 9.8) to bypass authentication and gain administrative access, enabling deployment of ransomware (including Jasmin and BianLian activity), XMRig cryptocurrency miners, Cobalt Strike beacons, and the Spark RAT; organizations using TeamCity are advised to patch immediately. The report also highlights broader ransomware trends, affiliate/RaaS behavior, and defense-evasion TTPs such as BYOVD and living-off-the-land techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
