logo

Untold Tales from Tactical Response | Huntress

ID: 69eae712-5695-5569-8c34-983b51ec2957

STIX ID: report--69eae712-5695-5569-8c34-983b51ec2957

Feed Name: Huntress Blog

Threat Score
72/100

Date Published: 2025-03-10

Date Updated: 2026-04-28

...
...

Huntress recounts an investigation where attackers gained foothold (likely via VPN brute-force), exploited a known Veeam Backup & Replication vulnerability (CVE-2023-27532) to extract credentials and execute code via Veeam.Backup.MountService.exe, then moved laterally using WinRM (wsmprovhost), created persistent local administrator/RDP accounts, and modified registry settings to enable further RDP access and bypass UAC; the report includes event/log evidence, process lineage, MITRE ATT&CK mapping, and applicable IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.