Veeam Vulnerability Exploited by Akira and Fog Ransomware (Campaign)
ID: 228589fc-28f9-5418-ba31-5313246fa35d
STIX ID: report--228589fc-28f9-5418-ba31-5313246fa35d
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2024-10-10
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
The report documents in-the-wild exploitation of CVE-2024-40711 in Veeam Backup & Replication by ransomware operators (Akira, Fog). Attackers chain the RCE with previously compromised credentials to create a local "point" admin account, leverage exposed VPN gateways without MFA, execute system commands via Veeam.Backup.MountService.exe on port 8000, and exfiltrate data using rclone, culminating in ransomware deployment and data theft.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
