Akira and Fog ransomware now exploit critical Veeam RCE flaw

Teilen:

Ransomware gangs now exploit a critical security vulnerability that lets attackers gain remote code execution (RCE) on vulnerable Veeam Backup & Replication (VBR) servers.

Code White security researcher Florian Hauser found that the security flaw, now tracked as CVE-2024-40711, is caused by a deserialization of untrusted data weakness that unauthenticated threat actors can exploit in low-complexity attacks.

Veeam disclosed the vulnerability and released security updates on September 4, while watchTowr Labs published a technical analysis on September 9. However, watchTowr Labs delayed publishing proof-of-concept exploit code until September 15 to give admins enough time to secure their servers.

The delay was prompted by businesses using Veeam’s VBR software as a data protection and disaster recovery solution for backing up, restoring, and replicating virtual, physical, and cloud machines.

This makes it a very popular target for malicious actors seeking quick access to a company’s backup data.

 

As Sophos X-Ops incident responders found over the last month, the CVE-2024-40711 RCE flaw was quickly picked up and exploited in Akira and Fog ransomware attacks together with previously compromised credentials to add a “point” local account to the local Administrators and Remote Desktop Users groups.

“In one case, attackers dropped Fog ransomware. Another attack in the same timeframe attempted to deploy Akira ransomware. Indicators in all 4 cases overlap with earlier Akira and Fog ransomware attacks,” Sophos X-Ops said.

“In each of the cases, attackers initially accessed targets using compromised VPN gateways without multifactor authentication enabled. Some of these VPNs were running unsupported software versions.

“In the Fog ransomware incident, the attacker deployed it to an unprotected Hyper-V server, then used the utility rclone to exfiltrate data.”

Not the first Veeam flaw targeted in ransomware attacks

Last year, on March 7, 2023, Veeam also patched a high-severity vulnerability in the Backup & Replication software (CVE-2023-27532) that can be exploited to breach backup infrastructure hosts.

Weeks later, in late March, Finnish cybersecurity and privacy company WithSecure spotted CVE-2023-27532 exploits deployed in attacks linked to the financially motivated FIN7 threat group, known for its links to the Conti, REvil, Maze, Egregor, and BlackBasta ransomware operations.

Months later, the same Veeam VBR exploit was used in Cuba ransomware attacks against U.S. critical infrastructure and Latin American IT companies.

Veeam says its products are used by over 550,000 customers worldwide, including at least 74% of all Global 2,000 companies.

Sergiu Gatlan

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
3:25 am, Juni 26, 2025
Wetter-Symbol 19°C
L: 18° | H: 20°
broken clouds
Luftfeuchtigkeit: 78 %
Druck: 1009 mb
Wind: 8 mph WNW
Windböe: 13 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 53%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:44 am
Sonnenuntergang: 9:21 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
18° | 20°°C 1 mm 100% 15 mph 85 % 1018 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
15° | 27°°C 0 mm 0% 13 mph 66 % 1022 mb 0 mm/h
Sa. Juni 28 10:00 pm
Wetter-Symbol
17° | 28°°C 0 mm 0% 10 mph 87 % 1024 mb 0 mm/h
So. Juni 29 10:00 pm
Wetter-Symbol
19° | 33°°C 0 mm 0% 10 mph 83 % 1025 mb 0 mm/h
Mo. Juni 30 10:00 pm
Wetter-Symbol
20° | 35°°C 0 mm 0% 13 mph 60 % 1019 mb 0 mm/h
Today 4:00 am
Wetter-Symbol
18° | 19°°C 0 mm 0% 8 mph 78 % 1009 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
19° | 19°°C 0 mm 0% 9 mph 78 % 1009 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
22° | 23°°C 0 mm 0% 13 mph 62 % 1010 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
20° | 20°°C 0.81 mm 81% 10 mph 85 % 1012 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
24° | 24°°C 1 mm 100% 15 mph 36 % 1012 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
21° | 21°°C 0.08 mm 8% 14 mph 36 % 1015 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
18° | 18°°C 0 mm 0% 10 mph 48 % 1018 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
16° | 16°°C 0 mm 0% 8 mph 59 % 1020 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€92,314.04
1.09%
Ethereum(ETH)
€2,112.91
0.26%
Fesseln(USDT)
€0.86
0.00%
XRP(XRP)
€1.88
0.37%
Solana(SOL)
€124.91
-0.29%
USDC(USDC)
€0.86
0.00%
Dogecoin(DOGE)
€0.142039
-0.41%
Shiba Inu(SHIB)
€0.000010
-0.40%
Pepe(PEPE)
€0.000009
-5.14%
Nach oben scrollen