News Room
16
Share
Operation CloudSieve: APT41 Exploits CVE-2026-63077 in TeamCity to Infiltrate Global Defense Supply Chains
criticalCyber Espionage

Operation CloudSieve: APT41 Exploits CVE-2026-63077 in TeamCity to Infiltrate Global Defense Supply Chains

A sophisticated espionage campaign is leveraging a critical RCE in TeamCity to deploy modular backdoors. The operation targets aerospace and defense sectors to exfiltrate proprietary R&D data.

12 August 2026Last updated 18 August 20265 min readCybelAngel / Mandiant
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here

Executive Takeaway — TL;DR

Category:
Cyber Espionage
Severity:
Critical
Actor Type:
Nation-State
Geography:
Global
Confidence:
High Confidence
CVE:
CVE-2026-63077
Source:
CybelAngel / Mandiant
Read Time:
5 min

Executive Summary

On August 10, 2026, intelligence analysts identified a widespread cyber espionage campaign, designated 'Operation CloudSieve,' targeting CI/CD (Continuous Integration/Continuous Deployment) infrastructure across North America and Southeast Asia. The campaign leverages a newly disclosed critical vulnerability, CVE-2026-63077, in JetBrains TeamCity servers. The primary objective appears to be the theft of intellectual property and sensitive research and development data from defense contractors and aerospace engineering firms. Encrygma's analysis suggests this is a highly coordinated effort to compromise the software supply chain at the source.

Threat Analysis

The threat actors are specifically targeting internet-facing TeamCity instances to gain initial access to corporate build environments. By compromising the CI/CD pipeline, the attackers can inject malicious code into legitimate software updates or steal environment variables, including AWS/Azure credentials and signing keys. This campaign represents a significant escalation in supply chain targeting, moving beyond simple data theft to the potential for long-term, persistent access within the development lifecycle of critical infrastructure providers.

Technical Details

The intrusion begins with the exploitation of CVE-2026-63077, a remote code execution (RCE) vulnerability that allows unauthenticated attackers to bypass security filters. Once access is gained, the actors deploy a custom, modular backdoor dubbed 'NullReceiver.' This malware utilizes a novel blockchain-based command-and-control (C2) mechanism. Specifically, it decodes its C2 IP address from the 'destination address' field of empty Ethereum transactions, a technique known as 'EtherHiding.'

Following the initial infection, the actors utilize a secondary persistence mechanism involving Microsoft Outlook. The malware queries the victim's calendar for a specific event planted far in the future (e.g., May 2050) to retrieve encrypted tasking instructions from an attached file. This 'Calendar-C2' method allows the traffic to blend seamlessly with legitimate Office 365 synchronization traffic, making detection by standard EDR solutions extremely difficult.

Attribution Assessment

We assess with high confidence that Operation CloudSieve is the work of APT41 (also known as Brass Typhoon or Wicked Panda). This assessment is based on the overlap in infrastructure, specifically the use of known APT41-linked proxy chains and the deployment of the 'SysUpdate' malware family, which has been historically exclusive to this group. The targeting of telecommunications and defense sectors aligns with the strategic intelligence requirements of the Chinese Ministry of State Security (MSS). Furthermore, the rapid weaponization of CVE-2026-63077 within 24 hours of its disclosure is consistent with APT41's operational tempo.

Implications

The compromise of CI/CD pipelines poses a systemic risk to the global technology ecosystem. If APT41 successfully signs malicious code with stolen certificates, the resulting downstream infections could mirror the scale of the 2020 SolarWinds incident. For the defense sector, the loss of proprietary aerospace designs directly impacts national security and technological parity. Organizations must assume that any build environment exposed to the internet during the last 48 hours is potentially compromised.

Recommendations

Encrygma recommends the following immediate actions:

  1. Immediate Patching: Update all TeamCity instances to the latest security release to mitigate CVE-2026-63077.
  2. Credential Rotation: Rotate all secrets, API keys, and signing certificates stored within CI/CD environment variables.
  3. Network Hunting: Scan for outbound connections to Ethereum blockchain explorers and anomalous Microsoft Graph API calls originating from build servers.
  4. Audit Logs: Review TeamCity access logs for unauthorized user creation or modifications to build configurations dating back to August 9, 2026.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo