• News/
  • https://www.theregister.com/2024/03/07/teamcity_exploits_lead_to_ransomware/

JetBrains TeamCity under attack by ransomware thugs after disclosure mess

The Register
·
Connor Jones
·
Published Mar 7, 2024
·
Updated

Security researchers are increasingly seeing active exploit attempts using the latest vulnerabilities in JetBrains' TeamCity that in some cases are leading to ransomware deployment. Brody Nisbet, director of threat hunting operations at security shop CrowdStrike, xeeted on Tuesday that telemetry was already showing signs of attacks using a suspected modified version of Jasmin ransomware. Jasmin is an open source red teaming tool that mimics WannaCry and is designed to help organizations simulate ransomware attacks, but it has been modified in the past for malicious purposes. The GoodWill ransomware variant was one such example from 2022 that locked victims out of their files but instead of demanding a ransom payment to a crypto address, victims had to fulfill good deeds like donating money to and feeding children in need. El Reg asked Nisbet for further information about what he saw but time zone differences meant we couldn't immediately connect. Other researchers have chimed in to say attacks using the pair of vulnerabilities, one critical and one high-severity, are well under way. Christiaan Beek, senior director of threat analytics at Rapid7, noted on AttackerKB that both TeamCity vulnerabilities were spotted being exploited in the wild. Security misconfiguration search engine LeakIX also said CVE-2024-27198, the most severe of the two vulnerabilities, was being exploited at a mass scale, with attackers breaking into CI/CD servers and creating hundreds of accounts for late...

Read full article

Affected Software

2 affected components
JetBrains TeamCity
JetBrains TeamCity=2023.11.4

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203