North Korean Actors Behind Active Exploitation of TeamCity Vulnerability
North Korean Actors Behind Active Exploitation of TeamCity Vulnerability
Threat Level
Attack Report
For a detailed threat advisory, download the pdf file here
Summary
The North Korean threat actors Lazarus and its subgroup Andariel are actively exploiting the CVE-2023-42793 vulnerability, which is an authentication bypass vulnerability, after successful exploitation, an attacker can perform a remote code execution attack and gain administrative control of the TeamCity server. These groups are deploying backdoor through this vulnerability, and their activities are likely aimed at conducting software supply chain attacks.
To receive real-time threat advisories, please follow HiveForce Labs on LinkedIn.