Akira and Fog ransomware now exploit critical Veeam RCE flaw

Share:

Ransomware gangs now exploit a critical security vulnerability that lets attackers gain remote code execution (RCE) on vulnerable Veeam Backup & Replication (VBR) servers.

Code White security researcher Florian Hauser found that the security flaw, now tracked as CVE-2024-40711, is caused by a deserialization of untrusted data weakness that unauthenticated threat actors can exploit in low-complexity attacks.

Veeam disclosed the vulnerability and released security updates on September 4, while watchTowr Labs published a technical analysis on September 9. However, watchTowr Labs delayed publishing proof-of-concept exploit code until September 15 to give admins enough time to secure their servers.

The delay was prompted by businesses using Veeam’s VBR software as a data protection and disaster recovery solution for backing up, restoring, and replicating virtual, physical, and cloud machines.

This makes it a very popular target for malicious actors seeking quick access to a company’s backup data.

 

As Sophos X-Ops incident responders found over the last month, the CVE-2024-40711 RCE flaw was quickly picked up and exploited in Akira and Fog ransomware attacks together with previously compromised credentials to add a “point” local account to the local Administrators and Remote Desktop Users groups.

“In one case, attackers dropped Fog ransomware. Another attack in the same timeframe attempted to deploy Akira ransomware. Indicators in all 4 cases overlap with earlier Akira and Fog ransomware attacks,” Sophos X-Ops said.

“In each of the cases, attackers initially accessed targets using compromised VPN gateways without multifactor authentication enabled. Some of these VPNs were running unsupported software versions.

“In the Fog ransomware incident, the attacker deployed it to an unprotected Hyper-V server, then used the utility rclone to exfiltrate data.”

Not the first Veeam flaw targeted in ransomware attacks

Last year, on March 7, 2023, Veeam also patched a high-severity vulnerability in the Backup & Replication software (CVE-2023-27532) that can be exploited to breach backup infrastructure hosts.

Weeks later, in late March, Finnish cybersecurity and privacy company WithSecure spotted CVE-2023-27532 exploits deployed in attacks linked to the financially motivated FIN7 threat group, known for its links to the Conti, REvil, Maze, Egregor, and BlackBasta ransomware operations.

Months later, the same Veeam VBR exploit was used in Cuba ransomware attacks against U.S. critical infrastructure and Latin American IT companies.

Veeam says its products are used by over 550,000 customers worldwide, including at least 74% of all Global 2,000 companies.

Sergiu Gatlan

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
1:33 pm, Jun 26, 2025
weather icon 22°C
L: 21° | H: 24°
heavy intensity rain
Humidity: 73 %
Pressure: 1010 mb
Wind: 15 mph SW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 6.39 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:44 am
Sunset: 9:21 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
21° | 24°°C 0.24 mm 24% 17 mph 62 % 1018 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
16° | 28°°C 0 mm 0% 13 mph 61 % 1021 mb 0 mm/h
Sat Jun 28 10:00 pm
weather icon
17° | 28°°C 0.2 mm 20% 10 mph 88 % 1025 mb 0 mm/h
Sun Jun 29 10:00 pm
weather icon
19° | 32°°C 0 mm 0% 6 mph 82 % 1025 mb 0 mm/h
Mon Jun 30 10:00 pm
weather icon
21° | 34°°C 0.2 mm 20% 12 mph 59 % 1019 mb 0 mm/h
Today 4:00 pm
weather icon
23° | 23°°C 0.24 mm 24% 17 mph 62 % 1011 mb 0 mm/h
Today 7:00 pm
weather icon
21° | 22°°C 0 mm 0% 13 mph 47 % 1013 mb 0 mm/h
Today 10:00 pm
weather icon
17° | 17°°C 0 mm 0% 10 mph 47 % 1018 mb 0 mm/h
Tomorrow 1:00 am
weather icon
16° | 16°°C 0 mm 0% 8 mph 57 % 1020 mb 0 mm/h
Tomorrow 4:00 am
weather icon
16° | 16°°C 0 mm 0% 6 mph 61 % 1020 mb 0 mm/h
Tomorrow 7:00 am
weather icon
17° | 17°°C 0 mm 0% 8 mph 59 % 1021 mb 0 mm/h
Tomorrow 10:00 am
weather icon
22° | 22°°C 0 mm 0% 11 mph 52 % 1021 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
26° | 26°°C 0 mm 0% 12 mph 46 % 1020 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€91,655.70
0.12%
Ethereum(ETH)
€2,088.99
0.96%
Tether(USDT)
€0.86
-0.02%
XRP(XRP)
€1.86
-1.10%
Solana(SOL)
€122.58
-1.63%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.137763
-2.20%
Shiba Inu(SHIB)
€0.000009
-2.16%
Pepe(PEPE)
€0.000008
-6.76%
Scroll to Top