logo

aa23-347a-russian-foreign-intelligence-service-svr-exploiting-jetbrains-teamcity-cve-globally.pdf

ID: 336dd90b-ad7f-4139-9b78-1fcee5a9a9bd

STIX ID: report--336dd90b-ad7f-4139-9b78-1fcee5a9a9bd

Threat Score

90/100

Uploaded: 2026-08-11

Published Date: 2023-12-13

Last Modified Date: 2023-12-13

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This joint advisory attributes a widespread exploitation campaign of JetBrains TeamCity (CVE-2023-42793) to the Russian Foreign Intelligence Service (SVR/APT29). It documents successful remote code execution against unpatched TeamCity servers since September 2023, post-exploitation activities (credential theft, EDR/AV bypass via EDRSandBlast, GraphicalProton backdoors using cloud-based steganography and HTTPS C2), observed victim types, actionable IOCs (file hashes, IPs, domains), detection SIGMA/YARA examples, and mitigation/incident-response recommendations urging organizations to assume compromise if unpatched.