
Operation CloudSieve: APT41 Exploits CVE-2026-63077 in TeamCity to Infiltrate Global Defense Supply Chains
A sophisticated espionage campaign is leveraging a critical RCE in TeamCity to deploy modular backdoors. The operation targets aerospace and defense sectors to exfiltrate proprietary R&D data.
Executive Takeaway — TL;DR
- Category:
- Cyber Espionage
- Severity:
- Critical
- Actor Type:
- Nation-State
- Geography:
- Global
- Confidence:
- High Confidence
- CVE:
- CVE-2026-63077
- Source:
- CybelAngel / Mandiant
- Read Time:
- 5 min
Executive Summary
On August 10, 2026, intelligence analysts identified a widespread cyber espionage campaign, designated 'Operation CloudSieve,' targeting CI/CD (Continuous Integration/Continuous Deployment) infrastructure across North America and Southeast Asia. The campaign leverages a newly disclosed critical vulnerability, CVE-2026-63077, in JetBrains TeamCity servers. The primary objective appears to be the theft of intellectual property and sensitive research and development data from defense contractors and aerospace engineering firms. Encrygma's analysis suggests this is a highly coordinated effort to compromise the software supply chain at the source.
Threat Analysis
The threat actors are specifically targeting internet-facing TeamCity instances to gain initial access to corporate build environments. By compromising the CI/CD pipeline, the attackers can inject malicious code into legitimate software updates or steal environment variables, including AWS/Azure credentials and signing keys. This campaign represents a significant escalation in supply chain targeting, moving beyond simple data theft to the potential for long-term, persistent access within the development lifecycle of critical infrastructure providers.
Technical Details
The intrusion begins with the exploitation of CVE-2026-63077, a remote code execution (RCE) vulnerability that allows unauthenticated attackers to bypass security filters. Once access is gained, the actors deploy a custom, modular backdoor dubbed 'NullReceiver.' This malware utilizes a novel blockchain-based command-and-control (C2) mechanism. Specifically, it decodes its C2 IP address from the 'destination address' field of empty Ethereum transactions, a technique known as 'EtherHiding.'
Following the initial infection, the actors utilize a secondary persistence mechanism involving Microsoft Outlook. The malware queries the victim's calendar for a specific event planted far in the future (e.g., May 2050) to retrieve encrypted tasking instructions from an attached file. This 'Calendar-C2' method allows the traffic to blend seamlessly with legitimate Office 365 synchronization traffic, making detection by standard EDR solutions extremely difficult.
Attribution Assessment
We assess with high confidence that Operation CloudSieve is the work of APT41 (also known as Brass Typhoon or Wicked Panda). This assessment is based on the overlap in infrastructure, specifically the use of known APT41-linked proxy chains and the deployment of the 'SysUpdate' malware family, which has been historically exclusive to this group. The targeting of telecommunications and defense sectors aligns with the strategic intelligence requirements of the Chinese Ministry of State Security (MSS). Furthermore, the rapid weaponization of CVE-2026-63077 within 24 hours of its disclosure is consistent with APT41's operational tempo.
Implications
The compromise of CI/CD pipelines poses a systemic risk to the global technology ecosystem. If APT41 successfully signs malicious code with stolen certificates, the resulting downstream infections could mirror the scale of the 2020 SolarWinds incident. For the defense sector, the loss of proprietary aerospace designs directly impacts national security and technological parity. Organizations must assume that any build environment exposed to the internet during the last 48 hours is potentially compromised.
Recommendations
Encrygma recommends the following immediate actions:
- Immediate Patching: Update all TeamCity instances to the latest security release to mitigate CVE-2026-63077.
- Credential Rotation: Rotate all secrets, API keys, and signing certificates stored within CI/CD environment variables.
- Network Hunting: Scan for outbound connections to Ethereum blockchain explorers and anomalous Microsoft Graph API calls originating from build servers.
- Audit Logs: Review TeamCity access logs for unauthorized user creation or modifications to build configurations dating back to August 9, 2026.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

China-Nexus 'Fire Ant' APT Infiltrates Cisco IOS XR Routers to Hijack Authentication Infrastructure

State-Sponsored Espionage Campaign Leverages ownCloud Flaw to Exfiltrate Philippine Nuclear Data

