logo

TeamCity Flaw Leads to Surge in Ransomware, Cryptomining, and RAT Attacks

ID: e224b513-8c04-5b6e-b73f-097d3a211ce1

STIX ID: report--e224b513-8c04-5b6e-b73f-097d3a211ce1

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2024-03-20

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Multiple threat actors are actively exploiting the critical JetBrains TeamCity vulnerability (CVE-2024-27198, CVSS 9.8) to bypass authentication and gain administrative access, enabling deployment of ransomware (including Jasmin and BianLian activity), XMRig cryptocurrency miners, Cobalt Strike beacons, and the Spark RAT; organizations using TeamCity are advised to patch immediately. The report also highlights broader ransomware trends, affiliate/RaaS behavior, and defense-evasion TTPs such as BYOVD and living-off-the-land techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.