aa23-347a-russian-foreign-intelligence-service-svr-exploiting-jetbrains-teamcity-cve-globally.pdf
ID: 336dd90b-ad7f-4139-9b78-1fcee5a9a9bd
STIX ID: report--336dd90b-ad7f-4139-9b78-1fcee5a9a9bd
Threat Score
90/100
Uploaded: 2026-08-11
Published Date: 2023-12-13
Last Modified Date: 2023-12-13
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This joint advisory attributes a widespread exploitation campaign of JetBrains TeamCity (CVE-2023-42793) to the Russian Foreign Intelligence Service (SVR/APT29). It documents successful remote code execution against unpatched TeamCity servers since September 2023, post-exploitation activities (credential theft, EDR/AV bypass via EDRSandBlast, GraphicalProton backdoors using cloud-based steganography and HTTPS C2), observed victim types, actionable IOCs (file hashes, IPs, domains), detection SIGMA/YARA examples, and mitigation/incident-response recommendations urging organizations to assume compromise if unpatched.
