logo

Veeam Vulnerability Exploited by Akira and Fog Ransomware (Campaign)

ID: 228589fc-28f9-5418-ba31-5313246fa35d

STIX ID: report--228589fc-28f9-5418-ba31-5313246fa35d

Feed Name: Wiz Cloud Threat Landscape

Threat Score
85/100

Date Published: 2024-10-10

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

The report documents in-the-wild exploitation of CVE-2024-40711 in Veeam Backup & Replication by ransomware operators (Akira, Fog). Attackers chain the RCE with previously compromised credentials to create a local "point" admin account, leverage exposed VPN gateways without MFA, execute system commands via Veeam.Backup.MountService.exe on port 8000, and exfiltrate data using rclone, culminating in ransomware deployment and data theft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.