Cloud Threat Landscape
  • Incidents
  • Actors
  • Techniques
  • Defenses
  • Tools
  • Targeted Technologies
  • Posters & Newspapers
  • About
  • RSS
  • STIX
  • Back to wiz.io
Cloud Threat Landscape
/Incidents
Incidents
/
Veeam Vulnerability Exploited by Akira and Fog Ransomware

Veeam Vulnerability Exploited by Akira and Fog Ransomware

Type
Campaign
Actors
❓Unknown
Pub. date
October 10, 2024
Initial access
1-day vulnerability
Impact
RansomOp
Observed techniques
Vulnerability exploitationValid creds abuse
Observed tools
Akira ransomwareFog ransomware
Targeted technologies
Veeam
References
https://infosec.exchange/@SophosXOps/113284564225476186https://www.bleepingcomputer.com/news/security/akira-and-fog-ransomware-now-exploiting-critical-veeam-rce-flaw/
Status
Finalized
Last edited
Oct 14, 2024 11:18 AM

CVE-2024-40711 arises from the deserialization of untrusted data in the Veeam Backup & Replication software. This vulnerability can be exploited with low-complexity attacks, making it a threat to organizations relying on Veeam’s platform for backup, disaster recovery, and data replication across virtual, physical, and cloud environments. Once exploited, the flaw enables attackers to remotely execute arbitrary code by triggering the vulnerable Veeam.Backup.MountService.exe process on URI /trigger over port 8000, which spawns system commands via net.exe.

Researchers observed that attackers are combining the CVE-2024-40711 exploit with previously compromised credentials to create a local account named "point." This account is added to the Administrators and Remote Desktop Users groups, granting attackers elevated privileges. During these attacks, the ransomware groups also used compromised VPN gateways, many of which lacked multifactor authentication (MFA) and were running outdated or unsupported software.

Researchers identified several ransomware deployments utilizing this exploit. In one instance, the Fog ransomware was deployed on an unprotected Hyper-V server, and data was exfiltrated using the rclone utility. Other attacks featured Akira ransomware.

Made with 💙 by Wiz

Last Updated: April 3, 2025