Threat Analysis: TeamCity Ransomware, Roundcube Exploits, and the ClickFix Social Engineering Wave

Threats & Attacks

Threat Analysis: TeamCity Ransomware, Roundcube Exploits, and the ClickFix Social Engineering Wave

This is your Daily Threat Analysis for 24th September 2026.

Three separate active threats today. They are not connected, but they share a common thread: all of them exploit the gap between a patch being available and a patch being applied. That gap is, as ever, where the damage gets done.

JetBrains TeamCity: Ransomware Gangs Are Now In

CISA has formally warned that ransomware groups are actively exploiting a critical remote code execution vulnerability in JetBrains TeamCity. The patch was issued in July. We are now in late September. That is roughly eleven weeks during which organisations running unpatched TeamCity installations have been sitting in front of an unlocked door.

The advisory stops at “ransomware gangs are exploiting this.” What it does not say is who your TeamCity server actually belongs to in practice. Many UK SMBs do not run their own CI/CD infrastructure, they rely on a managed service provider or a software development partner who does. If that is your situation, the question is not whether you patched TeamCity. The question is whether they did.

TeamCity is developer tooling. It sits inside build pipelines that often have elevated access to source code repositories, deployment credentials, and production environments. An attacker who compromises a TeamCity instance is not just inside one machine, they are potentially inside everything that machine touches. For businesses that use software development partners or outsourced IT with any kind of automated deployment pipeline, this is a supply chain exposure, not just a software vulnerability.

If your IT provider tells you this does not affect you because you do not run TeamCity yourself, ask them to confirm in writing that their own infrastructure is patched. Then ask what access their build systems have to your environment.

What to do: If you run TeamCity on-premises, apply the July patch immediately if you have not already. If a third party manages development infrastructure on your behalf, contact them today and request confirmation of their patch status. Log the response.

Roundcube Webmail: Actively Exploited, Four Months After the Fix

The Canadian Centre for Cyber Security has flagged that CVE-2026-48842, a high-severity code injection vulnerability in Roundcube Webmail, is now being actively exploited in the wild. The patch was available in May.

Roundcube is used in significant numbers by organisations that host their own email rather than using Microsoft 365 or Google Workspace, a common setup among UK professional services firms, legal practices, and accountancies that prefer not to hand their correspondence to a hyperscaler. It is also the webmail interface for a number of managed hosting packages sold to SMBs by UK and European hosting providers.

Code injection through a webmail vulnerability is particularly nasty because the attack surface is the inbox itself. A crafted email, opened in an unpatched Roundcube installation, can execute attacker-controlled code on the server. The user does not need to click a link or open an attachment. They just need to read their email.

The NCSC has published guidance on keeping webmail infrastructure patched. The fact we are still having this conversation about a flaw disclosed in May tells you everything about how seriously that guidance is being operationalised.

What to do: If your business uses Roundcube, either self-hosted or through a managed hosting package, check your version immediately and apply the May patch. If you are unsure whether your hosting provider uses Roundcube as the webmail interface, ask them directly. Do not wait for them to notify you.

ClickFix: The Social Engineering Campaign That Will Not Go Away

ClickFix deserves sustained attention because it has now been running as an active distribution method across multiple campaigns for months, and it keeps working because it exploits something patches cannot fix: people.

The technique is straightforward. A victim visits a page, often a fake CAPTCHA, a compromised legitimate website, or a fake software download, and is presented with an instruction: “To verify you are human, press Windows + R, paste this command, and press Enter.” The victim does so. The command they paste is malicious. The infection is immediate.

Three separate intelligence reports in today’s feed reference ClickFix as the initial access vector. PavinLoader uses it. AvisLoader uses it. The five-month bulletproof hosting campaign tracked by Black Hills Information Security used it across four distinct malware chains. The payloads vary, credential stealers, persistent loaders, blockchain-based command-and-control that survives traditional domain takedowns, but the entry point is the same.

AvisLoader is worth noting specifically. Its command-and-control infrastructure runs over the Tox encrypted peer-to-peer messaging network rather than traditional domains. You cannot take it down by seizing a domain. There is no central server to pull. This is infrastructure designed to outlast the defenders, and it starts with someone pasting a command into a Windows Run dialog because a webpage told them to.

The campaigns using ClickFix are currently targeting users broadly, fake software downloads, fake games, fake verification pages. UK SMB staff browsing for software, downloading productivity tools, or landing on compromised sites are in the target population. This is not sophisticated spearphishing aimed at executives. It is volume-based and it is effective.

What to do: Brief your staff. Show them what the attack looks like. “Windows + R then paste this” is never a legitimate verification step. No genuine website will ask you to run a command to prove you are human. If staff see this, they should close the page and report it. This takes fifteen minutes to explain and is currently more effective than any technical control at stopping the initial access.

A Note on the AI C2 Story

Cisco Talos published research today on CLOSEDQUORUM, a Windows implant that uses a panel of commercial large language models, DeepSeek, Qwen, Mistral, Gemini, to make tactical decisions via plurality vote rather than receiving instructions from an attacker’s server. This is genuinely novel research and it deserves attention.

I will say what the coverage is not saying clearly enough: Talos has not observed this working end-to-end in a real campaign. The public version of the malware does not currently function as described. This is proof-of-concept territory, not an active threat to UK SMBs today. Worth watching. Not worth panicking about this morning. The TeamCity and Roundcube situations are the immediate problems.

What Matters Today

Three items, in order of urgency:

  1. TeamCity, Verify patch status on your own infrastructure and any third-party infrastructure with access to your environment. Do it today.
  2. Roundcube, Check whether you or your hosting provider runs it. If yes, verify the May patch is applied.
  3. ClickFix, Brief your staff this week. Show them what the attack looks like. Make reporting it the default response.

None of this requires specialist tools. None of it requires budget. It requires someone picking up the phone and asking the right questions.

If Threat Analysis is useful to you, follow the show wherever you listen so tomorrow’s briefing lands automatically, and if you know someone who needs the heads-up, pass it along. The more people asking these questions, the fewer successful intrusions.


Sources

SourceTitleURL
BleepingComputerCISA: Ransomware gangs now exploiting critical TeamCity flawhttps://www.bleepingcomputer.com/news/security/cisa-ransomware-gangs-now-exploiting-critical-teamcity-flaw/
BleepingComputerHackers now exploit critical Roundcube flaw in code injection attackshttps://www.bleepingcomputer.com/news/security/critical-roundcube-flaw-now-actively-exploited-in-code-injection-attacks/
VaronisMeet AvisLoader: A Windows Loader Built to Outlast a Takedownhttps://www.varonis.com/blog/meet-avisloader-a-windows-loader-built-to-outlast-a-takedown
Black Hills Information Security / ActiveSOCDisposable Domains, Durable Hostinghttps://activesoc.blackhillsinfosec.com/blog/disposable-domains-durable-hosting
MalwarebytesTracking PavinLoader across ClickFix and fake download campaignshttps://www.malwarebytes.com/blog/threat-intel/2026/08/tracking-pavinloader-across-clickfix-and-fake-download-campaigns
Cisco TalosThe Closed Quorum: Inside the first reported autonomous AI C2 implanthttps://blog.talosintelligence.com/the-closed-quorum-inside-the-first-reported-autonomous-ai-c2-implant/

Filed under

  • ransomware-groups
  • smb-security
  • social-engineering
  • credential-theft
  • supply-chain-risk
  • vendor-risk
  • incident-response