HomeSecurityLazarus and Andariel hackers exploit TeamCity bug for network breaches

Lazarus and Andariel hackers exploit TeamCity bug for network breaches

Microsoft says North Korean hackers Lazarus and Andariel are exploiting the CVE-2023-42793 vulnerability in TeamCity servers to install a backdoor , aiming to conduct software supply chain attacks .

TeamCity is an integration and deployment server that organizations use as part of their software development infrastructure.

Andariel hackers Lazarus

In September, it fixed a critical vulnerability (CVE-2023-42793) that allowed unverified users to execute code remotely.

While the TeamCity vulnerability was quickly patched, malicious hackers , such as ransomware gangs , began exploiting it to compromise corporate networks.

See also: Lazarus hackers use new LightlessCan malware

North Korean hackers Lazarus and Andariel exploit TeamCity bug

According to a new report from Microsoft, hacking groups Lazarus and Andariel have been observed using CVE-2023-42793 to compromise TeamCity servers.

The ultimate goal of these attacks has not been stated with certainty, but it is believed that it could be to carry out software supply chain attacks.

According to Microsoft, in previous operations, Lazarus and other North Korean hackers have carried out such attacks by infiltrating build environments.

Once hackers compromise a TeamCity server, they use different attack chains to deploy backdoors and gain persistence on the compromised network.

The Lazarus hackers, for example, used the ForestTiger malware , which is used as a backdoor to execute commands on the compromised server.

See also: CoinEx: Are Lazarus hackers behind the hack?

A second attack chain uses DLL search order hijacking attacksto launch a malware loader called FeedLoad and install a remote access Trojan (RAT).

On the other hand, Andariel hackers create an administrator account “krtbgt” on the compromised server and execute commands to collect system.

TeamCity

The threat actors eventually deploy a payload that installs the HazyLoad proxy tool, which allows a persistent connection between the compromised server and the Andariel hackers' servers.

Microsoft shared more technical details about all the attacks it detected.

As the TeamCity bug shows, vulnerabilities are a significant risk factor in cybersecurity. They are errors or weaknesses that a cybercriminal can exploit to breach security systems, gain access to sensitive information, or cause other damage.

Lazarus and Andariel hackers

Both Lazarus and Andariel are state-sponsored North Korean hacking groups . Andariel is a sub-group of Lazarus. The groups' attacks are used to benefit the North Korean government, but they usually target different things.

See also: Lazarus Group: Exploits critical Zoho ManageEngine flaw to spread QuiteRAT

Lazarus hackers have been linked to various attacks . They often target security researchers, hack crypto platforms, and steal cryptocurrencies. There have also been many fake job interview that distribute malware.

On the other hand, the Andariel group targets defense and IT service entities in South Korea, the United States, and India to conduct espionage cyber

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS