North Korean Actors Behind Active Exploitation of TeamCity Vulnerability

Threat Advisories

North Korean Actors Behind Active Exploitation of TeamCity Vulnerability

Threat Level
Attack Report

For a detailed threat advisory, download the pdf file here

Summary

The North Korean threat actors Lazarus and its subgroup Andariel are actively exploiting the CVE-2023-42793 vulnerability, which is an authentication bypass vulnerability, after successful exploitation, an attacker can perform a remote code execution attack and gain administrative control of the TeamCity server. These groups are deploying backdoor through this vulnerability, and their activities are likely aimed at conducting software supply chain attacks.

To receive real-time threat advisories, please follow HiveForce Labs on LinkedIn.