Cyber Threat Report: 'Russian Foreign Intelligence Service (SVR) Exploiting JetBrains TeamCity CVE Globally'

Report Author CISA
Publication Date 2023-12-13
Original Reporting Source
Attributed to Nation Russia
Related Intrusion Sets Midnight Blizzard , NOBELIUM , Cozy Bear , The Dukes , APT29
Related Threat Actors SVR - Russian Foreign Intelligence Service
Identified CVEs CVE-2023-42793

This Cybersecurity Advisory by CISA with US and international partners outlines activity which they link to APT29 (also known as The Dukes, Cozy Bear, Midnight Blizzard) and the Russian Foreign Intelligence Service (SVR). The advisory contains technical details and MITRE ATT&CK techniques used by the group as part of a campaign which included exploitation of CVE-2023-42793 in Jet Brains' TeamCity at scale.

Cyber Threat Graph Context

Explore how this report relates to the wider threat graph

Mitigations to defend against the techniques in this report

Identified MITRE ATT&CK Techniques