Akira and Fog ransomware now exploit critical Veeam RCE flaw

Share:

Ransomware gangs now exploit a critical security vulnerability that lets attackers gain remote code execution (RCE) on vulnerable Veeam Backup & Replication (VBR) servers.

Code White security researcher Florian Hauser found that the security flaw, now tracked as CVE-2024-40711, is caused by a deserialization of untrusted data weakness that unauthenticated threat actors can exploit in low-complexity attacks.

Veeam disclosed the vulnerability and released security updates on September 4, while watchTowr Labs published a technical analysis on September 9. However, watchTowr Labs delayed publishing proof-of-concept exploit code until September 15 to give admins enough time to secure their servers.

The delay was prompted by businesses using Veeam’s VBR software as a data protection and disaster recovery solution for backing up, restoring, and replicating virtual, physical, and cloud machines.

This makes it a very popular target for malicious actors seeking quick access to a company’s backup data.

 

As Sophos X-Ops incident responders found over the last month, the CVE-2024-40711 RCE flaw was quickly picked up and exploited in Akira and Fog ransomware attacks together with previously compromised credentials to add a “point” local account to the local Administrators and Remote Desktop Users groups.

“In one case, attackers dropped Fog ransomware. Another attack in the same timeframe attempted to deploy Akira ransomware. Indicators in all 4 cases overlap with earlier Akira and Fog ransomware attacks,” Sophos X-Ops said.

“In each of the cases, attackers initially accessed targets using compromised VPN gateways without multifactor authentication enabled. Some of these VPNs were running unsupported software versions.

“In the Fog ransomware incident, the attacker deployed it to an unprotected Hyper-V server, then used the utility rclone to exfiltrate data.”

Not the first Veeam flaw targeted in ransomware attacks

Last year, on March 7, 2023, Veeam also patched a high-severity vulnerability in the Backup & Replication software (CVE-2023-27532) that can be exploited to breach backup infrastructure hosts.

Weeks later, in late March, Finnish cybersecurity and privacy company WithSecure spotted CVE-2023-27532 exploits deployed in attacks linked to the financially motivated FIN7 threat group, known for its links to the Conti, REvil, Maze, Egregor, and BlackBasta ransomware operations.

Months later, the same Veeam VBR exploit was used in Cuba ransomware attacks against U.S. critical infrastructure and Latin American IT companies.

Veeam says its products are used by over 550,000 customers worldwide, including at least 74% of all Global 2,000 companies.

Sergiu Gatlan

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
1:21 pm, Jun 22, 2025
weather icon 25°C
L: 24° | H: 26°
scattered clouds
Humidity: 49 %
Pressure: 1013 mb
Wind: 15 mph WSW
Wind Gust: 19 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 40%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:43 am
Sunset: 9:21 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
24° | 26°°C 0 mm 0% 17 mph 64 % 1013 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
15° | 23°°C 0.2 mm 20% 15 mph 81 % 1016 mb 0 mm/h
Tue Jun 24 10:00 pm
weather icon
14° | 26°°C 0 mm 0% 16 mph 77 % 1015 mb 0 mm/h
Wed Jun 25 10:00 pm
weather icon
16° | 27°°C 0 mm 0% 9 mph 86 % 1013 mb 0 mm/h
Thu Jun 26 10:00 pm
weather icon
17° | 24°°C 1 mm 100% 15 mph 95 % 1018 mb 0 mm/h
Today 4:00 pm
weather icon
21° | 24°°C 0 mm 0% 17 mph 47 % 1013 mb 0 mm/h
Today 7:00 pm
weather icon
21° | 22°°C 0 mm 0% 13 mph 54 % 1012 mb 0 mm/h
Today 10:00 pm
weather icon
16° | 16°°C 0 mm 0% 10 mph 64 % 1012 mb 0 mm/h
Tomorrow 1:00 am
weather icon
16° | 16°°C 0 mm 0% 13 mph 76 % 1011 mb 0 mm/h
Tomorrow 4:00 am
weather icon
16° | 16°°C 0.2 mm 20% 13 mph 81 % 1011 mb 0 mm/h
Tomorrow 7:00 am
weather icon
15° | 15°°C 0.2 mm 20% 13 mph 60 % 1013 mb 0 mm/h
Tomorrow 10:00 am
weather icon
17° | 17°°C 0 mm 0% 13 mph 46 % 1014 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
21° | 21°°C 0 mm 0% 12 mph 32 % 1015 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€89,150.11
-1.15%
Ethereum(ETH)
€1,976.75
-6.75%
Tether(USDT)
€0.87
0.02%
XRP(XRP)
€1.75
-5.46%
Solana(SOL)
€115.89
-6.07%
USDC(USDC)
€0.87
0.00%
Dogecoin(DOGE)
€0.135155
-4.58%
Shiba Inu(SHIB)
€0.000010
-5.08%
Pepe(PEPE)
€0.000008
-8.70%
Peanut the Squirrel(PNUT)
€0.218233
13.10%
Scroll to Top