BianLian Threat Actors Exploiting JetBrains TeamCity Flaws in Ransomware Attacks

The threat actors responsible for the BianLian ransomware have been seen using security holes in JetBrains TeamCity software to carry out their attacks, which are limited to extortion.

A recent intrusion prompted GuidePoint Security to release a report in which it stated that the incident “began with the exploitation of a TeamCity server which resulted in the deployment of a PowerShell implementation of BianLian’s Go backdoor.”

Having first surfaced in June 2022, BianLian has since changed its focus to extortion based on exfiltration when a decryptor was made public in January 2023.

The cybersecurity firm observed an attack chain that involves the use of CVE-2024-27198 or CVE-2023-42793 to exploit a vulnerable TeamCity instance to obtain initial access to the environment read more BianLian Threat Actors Exploiting JetBrains TeamCity Flaws in Ransomware Attacks.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *