EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Ransomware

Russian Foreign Intelligence Service (SVR) Exploiting JetBrains TeamCity CVE Globally

Official source
EudorIA operational summary

What it means

Priority 90/100

CISA Cybersecurity Advisories ha pubblicato un advisory sul ransomware Russian Foreign Intelligence Service (SVR) Exploiting JetBrains TeamCity CVE Globally. Le misure indicate vanno confrontate con esposizione, identita, segmentazione e capacita di ripristino.

Why it matters

L'advisory descrive attivita ransomware osservate e misure difensive pubblicate da un'autorita. Non prova che il proprio perimetro sia compromesso, ma richiede una verifica prioritaria di esposizione e controlli.

Potential operational benefits

  • Prioritizzazione delle esposizioni Internet e delle vulnerabilita sfruttate
  • Verifica dei controlli su accessi remoti, movimento laterale ed esfiltrazione
  • Validazione documentata della capacita di ripristino
Indications to confirm against the customer's technical and organisational perimeter.
Relevant controlsVulnerability managementIdentity and access managementNetwork segmentationBackup and recoveryDetection and response
AudienceITSOCCISOManagement
Information centre

Translation in progress

CISA

The official content is available in the original language. The Italian version will be published once automated checks are complete.

Text acquired from the source

Cybersecurity Advisory Russian Foreign Intelligence Service (SVR) Exploiting JetBrains TeamCity CVE Globally Release Date December 13, 2023 Alert Code AA23-347A Related topics: Nation-State Threats , Cyber Threats and Response , Securing Networks SUMMARY The U.S. Federal Bureau of Investigation (FBI), U.S. Cybersecurity & Infrastructure Security Agency (CISA), U.S. National Security Agency (NSA), Polish Military Counterintelligence Service (SKW), CERT Polska (CERT.PL), and the UK’s National Cyber Security Centre (NCSC) assess Russian Foreign Intelligence Service (SVR) cyber actors—also known as Advanced Persistent Threat 29 (APT 29), the Dukes, CozyBear, and NOBELIUM/Midnight Blizzard—are exploiting CVE-2023-42793 at a large scale, targeting servers hosting JetBrains TeamCity software since September 2023. Software developers use TeamCity software to manage and automate software compilation, building, testing, and releasing. If compromised, access to a TeamCity server would provide malicious actors with access to that software developer’s source code, signing certificates, and the ability to subvert software compilation and deployment processes—access a malicious actor could further use to conduct supply chain operations. Although the SVR used such access to compromise SolarWinds and its customers in 2020, limited number and seemingly opportunistic types of victims currently identified, indicate that the SVR has not used the access afforded by the TeamCity CVE in a similar manner. The SVR has, however, been observed using the initial access gleaned by exploiting the TeamCity CVE to escalate its privileges, move laterally, deploy additional backdoors, and take other steps to ensure persistent and long-term access to the compromised network environments. To bring Russia’s

Indicatori CISA verificabili

53 valori IOC dalla fonte ufficiale. Non sono una lista di blocco automatica: verificare data, contesto e applicabilita.

Ultima verifica: 2026-09-26T07:02:11.732793+00:00

Scarica STIX 2.1
TipoIndicatore (non cliccabile)File
domain-namematclick[.]com
urlhttps://MATCLICK[.]COM/WP-QUERY[.]PHP
ipv4-addr103[.]76[.]128[.]34
ipv4-addr65[.]21[.]51[.]58
ipv4-addr65[.]20[.]97[.]203
SHA-256950adbaf66ab214de837e6f1c00921c501746616a882ea8c42f1bad5f9b6eff4
MD55a782bc5f0d63540b666f6a07e116d81
SHA-1281bb0dadc789b89f7ae30d5f4bdeae57c66b0e1
SHA-2564ee70128c70d646c5c2a9a17ad05949cb1fbf1043e9d671998812b2dce75cf0f
SSDEEP49152:4WoDnIQuVStaakknRDxKMQMjxKrj28BEdJII60KUvFMDZUxIqM/+1UzzZZBx+/EG:XoDIQshar5P56NEdK8KUtMdUxtX0BxSR
SHA-256d724728344fcf3812a0664a80270f7b4980b82342449a8c5a2fa510e10600443
SHA-256f6194121e1540c3553273709127dfa1daab96b0acfab6e92548bfb4059913c69
SHA-256c832462c15c8041191f190f7a88d25089d57f78e97161c3003d68d0cc2c4baa3
SHA-256c40a8006a7b1f10b1b42fdd8d6d0f434be503fb3400fb948ac9ab8ddfa5b78a0
SHA-256c37c109171f32456bbe57b8676cc533091e387e6ba733fbaa01175c43cfb6ebd
SHA-256b53e27c79eed8531b1e05827ace2362603fb9f77f53cee2e34940d570217cbf7
SHA-25692c7693e82a90d08249edeafbca6533fed81b62e9e056dec34c24756e0a130a6
SHA-256219fb90d2e88a2197a9e08b0e7811e2e0bd23d59233287587ccc4642c2cf3d67
SHA-2561e74cf0223d57fd846e171f4a58790280d4593df1f23132044076560a5455ff8
SHA-25619f1ef66e449cf2a2b0283dbb756850cca396114286e1485e35e6c672c9c3641
SHA-25618101518eae3eec6ebe453de4c4c380160774d7c3ed5c79e1813013ac1bb0b93
SHA-2564bf1915785d7c6e0987eb9c15857f7ac67dc365177a1707b14822131d43a6166
SHA-256c7b01242d2e15c3da0f45b8adec4e6913e534849cde16a2a6c480045e03fbee4
SHA-256f1b40e6e5a7cbc22f7a0bd34607b13e7e3493b8aad7431c47f1366f0256e23eb
SHA-256ebe231c90fad02590fc56d5840acc63b90312b0e2fee7da3c7606027ed92600e
SHA-256cd3584d61c2724f927553770924149bb51811742a461146b15b34a26c92cad43
SHA-256971f0ced6c42dd2b6e3ea3e6c54d0081cf9b06e79a38c2ede3a2c5228c27a6dc
MD5347b4f985414ca9f78bbbbff002e3ec6
SHA-1a4b03f1e981ccdd7e08e786c72283d5551671edf
SHA-2568afb71b7ce511b0bce642f46d6fc5dd79fad86a58223061b684313966efef9c7
SSDEEP24576:finmTffpaWRle7THhimdPKz6v529zfrhxIFxSwNFdi2GM8:finkaWRleXlT2hqFxSwk5
SHA-2567b666b978dbbe7c032cef19a90993e8e4922b743ee839632bfa6d99314ea6c53
MD598a082e95628b51307343581cfb7eac7
SHA-1d4411f70e0dcc2f88d74ae7251d51c6676075f6f
SHA-256620d2bf14fe345eef618fdd1dac242b3a0bb65ccb75699fe00f7c671f2c1d869
SSDEEP24576:J5nPhOKYC39U8ZZHgMQZP7TQVtCqKWLyVtpMQvG20gF:JpJOe283wP7UnCqKhYf
SHA-25634c8f155601a3948ddb0d60b582cfe87de970d443cc0e05df48b1a1ad2e42b5e
SHA-25601b5f7094de0b2c6f8e28aa9a2ded678c166d615530e595621e692a9c0240732
MD569538d033ae3309f0652ae815506fcec
SHA-12df317b8a408d2ad5c94b9de6f20bbef03e46066
SHA-256773f0102720af2957859d6930cd09693824d87db705b3303cef9ee794375ce13
SSDEEP24576:Lv/5UHdNxRCMk9+Ew2NTHQx/CfRKGyvOK26/dDF4:9UHdNzFx2RH9y0
MD52d8e4f38b36c334d0a32a7324832501d
SHA-1f6f11ad2cd2b0cf95ed42324876bee1d83e01775
SHA-25601aa278b07b58dc46c84bd0b1b5c8e9ee4e62ea0bf7a695862444af32e87f1fd
SSDEEP192:PXieNdtikfKSLPMsDvUDkGtVkUTgBxe1HCjT+pdhh2nhpml0idEC8jSJUbueqeul:PXiQKSLPMo0IKP72hpm5dECdUb+eul
MD546125424b4982c6ae17af821dedb9bfbpayload.bin
SHA-118192bb4aaa1b72104be4d26460b55f31ca65bafpayload.bin
SHA-256cb83e5cb264161c28de76a44d0edb450745e773d24bec5869d85f69633e44dcfpayload.bin
MD5c996d7971c49252c582171d9380360f20296e2ce999e67c76352613a718e11516fe1b0efc3ffdb8918fc999dd76a73a5.bin
SHA-1c948ae14761095e4d76b55d9de86412258be7afd0296e2ce999e67c76352613a718e11516fe1b0efc3ffdb8918fc999dd76a73a5.bin
SHA-2560296e2ce999e67c76352613a718e11516fe1b0efc3ffdb8918fc999dd76a73a50296e2ce999e67c76352613a718e11516fe1b0efc3ffdb8918fc999dd76a73a5.bin
SSDEEP192:QGkygXkI925h0rx/jPdQUorjs/6gfyowJL/aMjGwP7eMa8Ep+ebMwfPZgjlJMSJ:hkyg0I9+0rljPaNI6iYJLWWEfbHH6jV0296e2ce999e67c76352613a718e11516fe1b0efc3ffdb8918fc999dd76a73a5.bin

Provenance

Allegato ufficiale CISA · 2023-12-13T16:25:56Z

SHA-512: 46cc498e4619d5c3433b56730a82900b4908b869bd31cbffb23d996c184c4e8345c25aabb5edb7270019fd6443db23efb50f74bc5735308ea63352a1fc5c9f65

Source
CISA Cybersecurity Advisories
Publishing entity
CISA
Entity type
National authority
Area
North America · US
Original language
en · translation in preparation
Publication
13/12/2023 13:00
Sharing
TLP:CLEAR
MITRE ATT&CK
T1003, T1003.001, T1003.002, T1020, T1027.001, T1033, T1036, T1041, T1046, T1047, T1049, T1053.005, T1055, T1057, T1059.001, T1059.003, T1068, T1098, T1190, T1203, T1210, T1505.001, T1547, T1555.003, T1558.001, T1562.001, T1564, T1564.001, T1567, T1568, T1572, T1574.002, T1590, T1590.004, T1592.002
CVE
CVE-2023-42793
Classification
Critical
Stated country
US
Technical scope

Affected products and versions

Verification in progress
Information not yet acquired.

The collector will check NVD and the available official vendor advisories.

Action indicated by the source

Verificare e correggere con priorita i sistemi Internet-facing indicati dalla fonte; applicare MFA resistente al phishing, segmentazione e backup offline immutabili con prove di ripristino.

Official technical references

Open the original source