logo

You had a year to patch this Veeam flaw and now it's going to hurt

ID: bf0ee7ad-2c70-5e92-878f-9800066f680d

STIX ID: report--bf0ee7ad-2c70-5e92-878f-9800066f680d

Feed Name: The Register (Security)

Threat Score
78/100

Date Published: 2024-07-11

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

EstateRansomware is an emerging ransomware group observed exploiting an unpatched Veeam Backup & Replication vulnerability (CVE-2023-27532) to gain control of backup servers and deploy a LockBit 3.0 variant. Analysts describe initial access via brute-forced FortiGate SSL VPN credentials (a dormant 'Acc1' account), remote desktop-based lateral movement into Veeam failover and file servers, credential harvesting with tools like SoftPerfect Netscan and Nirsoft, and exploitation using publicly available proof-of-concept code. The intruders then escalate access to Active Directory, disable Windows Defender, clear logs and encrypt files, underscoring the critical need for timely patching and credential hygiene.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.