North Korean Actors Behind Active Exploitation of TeamCity Vulnerability

Threat Level – Red | Vulnerability Report
Download PDF

The North Korean threat actors Lazarus and its subgroup Andariel are actively exploiting the CVE-2023-42793 vulnerability, which is an authentication bypass vulnerability, after successful exploitation, an attacker can perform a remote code execution attack and gain administrative control of the TeamCity server. These groups are deploying backdoor through this vulnerability, and their activities are likely aimed at conducting software supply chain attacks.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox