logo

New Ransomware Group Exploiting Veeam Backup Software Vulnerability

ID: 2a700aee-f118-5255-bcb2-ae068b993290

STIX ID: report--2a700aee-f118-5255-bcb2-ae068b993290

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2024-07-10

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

Group-IB and other vendors observed active exploitation of a patched Veeam Backup & Replication vulnerability (CVE-2023-27532) by ransomware groups (EstateRansomware and Akira). Attackers gained access via a dormant FortiGate SSL VPN account, moved laterally to a failover/backup server, deployed a persistent backdoor (svchost.exe), enabled xp_cmdshell to create a 'VeeamBkp' account, harvested credentials, disabled Windows Defender, exfiltrated data, and deployed ransomware—demonstrating a high-impact supply-side attack against backup infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.