Patch or Peril: A Veeam vulnerability incident
ID: 9212504e-3933-5af3-9406-48cdc7fcef07
STIX ID: report--9212504e-3933-5af3-9406-48cdc7fcef07
Feed Name: Group-IB Blog
This Group-IB DFIR analysis describes an April 2024 estate ransomware incident where attackers used a dormant FortiGate SSL VPN account to access a failover server, deployed a persistent svchost backdoor (C2 at 77.238.245.11:30001), likely exploited CVE-2023-27532 against Veeam Backup & Replication to enable xp_cmdshell and create a VeeamBkp account, harvested credentials with NirSoft tools and AdFind, disabled Windows Defender, and deployed LB3.exe (EstateRansomware) across the environment; the report provides IOCs, MITRE ATT&CK mappings, and hardening recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
