Akira and Fog ransomware now exploit critical Veeam RCE flaw

Share:

Ransomware gangs now exploit a critical security vulnerability that lets attackers gain remote code execution (RCE) on vulnerable Veeam Backup & Replication (VBR) servers.

Code White security researcher Florian Hauser found that the security flaw, now tracked as CVE-2024-40711, is caused by a deserialization of untrusted data weakness that unauthenticated threat actors can exploit in low-complexity attacks.

Veeam disclosed the vulnerability and released security updates on September 4, while watchTowr Labs published a technical analysis on September 9. However, watchTowr Labs delayed publishing proof-of-concept exploit code until September 15 to give admins enough time to secure their servers.

The delay was prompted by businesses using Veeam’s VBR software as a data protection and disaster recovery solution for backing up, restoring, and replicating virtual, physical, and cloud machines.

This makes it a very popular target for malicious actors seeking quick access to a company’s backup data.

 

As Sophos X-Ops incident responders found over the last month, the CVE-2024-40711 RCE flaw was quickly picked up and exploited in Akira and Fog ransomware attacks together with previously compromised credentials to add a “point” local account to the local Administrators and Remote Desktop Users groups.

“In one case, attackers dropped Fog ransomware. Another attack in the same timeframe attempted to deploy Akira ransomware. Indicators in all 4 cases overlap with earlier Akira and Fog ransomware attacks,” Sophos X-Ops said.

“In each of the cases, attackers initially accessed targets using compromised VPN gateways without multifactor authentication enabled. Some of these VPNs were running unsupported software versions.

“In the Fog ransomware incident, the attacker deployed it to an unprotected Hyper-V server, then used the utility rclone to exfiltrate data.”

Not the first Veeam flaw targeted in ransomware attacks

Last year, on March 7, 2023, Veeam also patched a high-severity vulnerability in the Backup & Replication software (CVE-2023-27532) that can be exploited to breach backup infrastructure hosts.

Weeks later, in late March, Finnish cybersecurity and privacy company WithSecure spotted CVE-2023-27532 exploits deployed in attacks linked to the financially motivated FIN7 threat group, known for its links to the Conti, REvil, Maze, Egregor, and BlackBasta ransomware operations.

Months later, the same Veeam VBR exploit was used in Cuba ransomware attacks against U.S. critical infrastructure and Latin American IT companies.

Veeam says its products are used by over 550,000 customers worldwide, including at least 74% of all Global 2,000 companies.

Sergiu Gatlan

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
2:16 am, Jun 26, 2025
weather icon 20°C
L: 18° | H: 21°
overcast clouds
Humidity: 75 %
Pressure: 1009 mb
Wind: 8 mph WSW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:44 am
Sunset: 9:21 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
18° | 21°°C 1 mm 100% 15 mph 85 % 1018 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
15° | 27°°C 0 mm 0% 13 mph 66 % 1022 mb 0 mm/h
Sat Jun 28 10:00 pm
weather icon
17° | 28°°C 0 mm 0% 10 mph 87 % 1024 mb 0 mm/h
Sun Jun 29 10:00 pm
weather icon
19° | 33°°C 0 mm 0% 10 mph 83 % 1025 mb 0 mm/h
Mon Jun 30 10:00 pm
weather icon
20° | 35°°C 0 mm 0% 13 mph 60 % 1019 mb 0 mm/h
Today 4:00 am
weather icon
18° | 19°°C 0 mm 0% 8 mph 78 % 1009 mb 0 mm/h
Today 7:00 am
weather icon
19° | 19°°C 0 mm 0% 9 mph 76 % 1010 mb 0 mm/h
Today 10:00 am
weather icon
23° | 23°°C 0 mm 0% 13 mph 54 % 1011 mb 0 mm/h
Today 1:00 pm
weather icon
20° | 20°°C 0.81 mm 81% 10 mph 85 % 1012 mb 0 mm/h
Today 4:00 pm
weather icon
24° | 24°°C 1 mm 100% 15 mph 36 % 1012 mb 0 mm/h
Today 7:00 pm
weather icon
21° | 21°°C 0.08 mm 8% 14 mph 36 % 1015 mb 0 mm/h
Today 10:00 pm
weather icon
18° | 18°°C 0 mm 0% 10 mph 48 % 1018 mb 0 mm/h
Tomorrow 1:00 am
weather icon
16° | 16°°C 0 mm 0% 8 mph 59 % 1020 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€91,887.81
0.89%
Ethereum(ETH)
€2,077.34
-1.26%
Tether(USDT)
€0.86
0.01%
XRP(XRP)
€1.87
-0.31%
Solana(SOL)
€123.38
-1.31%
USDC(USDC)
€0.86
0.00%
Dogecoin(DOGE)
€0.140914
-0.88%
Shiba Inu(SHIB)
€0.000010
-0.80%
Pepe(PEPE)
€0.000009
-5.71%
Scroll to Top