• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
bianlian threat actors exploiting jetbrains teamcity flaws in ransomware attacks

BianLian Threat Actors Exploiting JetBrains TeamCity Flaws in Ransomware Attacks

You are here: Home / General Cyber Security News / BianLian Threat Actors Exploiting JetBrains TeamCity Flaws in Ransomware Attacks
March 11, 2024

The risk actors behind the BianLian ransomware have been observed exploiting security flaws in JetBrains TeamCity program to conduct their extortion-only attacks.

In accordance to a new report from GuidePoint Security, which responded to a modern intrusion, the incident “commenced with the exploitation of a TeamCity server which resulted in the deployment of a PowerShell implementation of BianLian’s Go backdoor.”

BianLian emerged in June 2022, and has considering the fact that pivoted exclusively to exfiltration-based mostly extortion following the release of a decryptor in January 2023.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


Cybersecurity

The attack chain noticed by the cybersecurity agency entails the exploitation of a vulnerable TeamCity occasion employing CVE-2024-27198 or CVE-2023-42793 to gain first access to the environment, adopted by developing new customers in the develop server and executing destructive instructions for publish-exploitation and lateral movement.

It is at the moment not apparent which of the two flaws ended up weaponized by the threat actor for infiltration.

BianLian actors are acknowledged to implant a custom backdoor tailored to each target prepared in Go, as very well as fall distant desktop tools like AnyDesk, Atera, SplashTop, and TeamViewer. The backdoor is tracked by Microsoft as BianDoor.

“Following numerous failed tries to execute their normal Go backdoor, the threat actor pivoted to living-off-the-land and leveraged a PowerShell implementation of their backdoor, which delivers an practically equivalent features to what they would have with their Go backdoor,” security researchers Justin Timothy, Gabe Renfro, and Keven Murphy mentioned.

The obfuscated PowerShell backdoor (“web.ps1”) is made to create a TCP socket for supplemental network conversation to an actor-managed server, allowing for the distant attackers to conduct arbitrary actions on an infected host.

“The now-verified backdoor is able to communicate with the [command-and-control] server and asynchronously execute dependent on the remote attacker’s post-exploitation aims,” the researchers said.

The disclosure will come as VulnCheck detailed refreshing proof-of-principle (PoC) exploits for a critical security flaw impacting Atlassian Confluence Details Middle and Confluence Server (CVE-2023-22527) that could guide to distant code execution in a fileless method and load the Godzilla web shell immediately into memory.

Cybersecurity

The flaw has considering that been weaponized to deploy C3RB3R ransomware, cryptocurrency miners and remote obtain trojans in excess of the previous two months, indicating common exploitation in the wild.

“There is far more than one particular way to achieve Rome,” VulnCheck’s Jacob Baines famous. “Whilst applying freemarker.template.utility.Execute appears to be the popular way of exploiting CVE-2023-22527, other extra stealthy paths generate unique indicators.”

Discovered this report interesting? Stick to us on Twitter  and LinkedIn to go through more special material we post.


Some components of this write-up are sourced from:
thehackernews.com

Previous Post: «proof of concept exploit released for progress software openedge vulnerability Proof-of-Concept Exploit Released for Progress Software OpenEdge Vulnerability
Next Post: Data Leakage Prevention in the Age of Cloud Computing: A New Approach data leakage prevention in the age of cloud computing: a»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.