logo

Patch or Peril: A Veeam vulnerability incident

ID: 9212504e-3933-5af3-9406-48cdc7fcef07

STIX ID: report--9212504e-3933-5af3-9406-48cdc7fcef07

Feed Name: Group-IB Blog

Threat Score
75/100

Date Published: 2024-07-10

Date Updated: 2026-04-28

...
...

This Group-IB DFIR analysis describes an April 2024 estate ransomware incident where attackers used a dormant FortiGate SSL VPN account to access a failover server, deployed a persistent svchost backdoor (C2 at 77.238.245.11:30001), likely exploited CVE-2023-27532 against Veeam Backup & Replication to enable xp_cmdshell and create a VeeamBkp account, harvested credentials with NirSoft tools and AdFind, disabled Windows Defender, and deployed LB3.exe (EstateRansomware) across the environment; the report provides IOCs, MITRE ATT&CK mappings, and hardening recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.