{"id":2678,"date":"2024-10-14T15:37:16","date_gmt":"2024-10-14T14:37:16","guid":{"rendered":"https:\/\/aegislens.com\/home\/?p=2678"},"modified":"2024-10-14T15:37:16","modified_gmt":"2024-10-14T14:37:16","slug":"exploring-the-exploitation-of-critical-veeam-vulnerability-the-diffusion-of-akira-and-fog-ransomware-explained","status":"publish","type":"post","link":"https:\/\/aegislens.com\/home\/exploring-the-exploitation-of-critical-veeam-vulnerability-the-diffusion-of-akira-and-fog-ransomware-explained\/","title":{"rendered":"Exploring the Exploitation of Critical Veeam Vulnerability: The Diffusion of Akira and Fog Ransomware Explained"},"content":{"rendered":"<p>Common Vulnerability Scoring System (CVSS), is a critical privilege escalation vulnerability that allows remote attackers to bypass authentication and execute arbitrary code.<\/p>\n<p>Veeam announced the discovery of this vulnerability on March 22 and issued out a patch.<\/p>\n<h2>The Method of Attack<\/h2>\n<p>The threat actors start by compromising VPN credentials to gain internal network access and then leverage the CVE-2024-40711 vulnerability to escalate privileges within the network.<\/p>\n<p>The actors create new local accounts in the infected system (sometimes with arbitrary names) which are then used to execute the ransomware.<\/p>\n<p>The Akira and Fog ransomware variants are being increasingly deployed in cyberattacks due to their ability to efficiently encrypt a victim&#8217;s data and demand a ransom.<\/p>\n<h2>Unpatched Systems at Risk<\/h2>\n<p>Veeam warns that all unpatched systems remain at incessant risk of cyberattacks that can result in significant data loss and business disturbance.<\/p>\n<p>In response to the Veeam vulnerability, the cybersecurity community has urged organizations to promptly apply the security updates to mitigate the potential risks<\/p>\n<p>.<\/p>\n<h2>Real-World Example<\/h2>\n<p>An example of the real-world impact of this vulnerability was seen when a Europe-based manufacturing company fell victim to the Akira ransomware after attackers exploited the CVE-2024-40711 vulnerability in their Veeam backup server.<\/p>\n<p>The attack led to massive data loss and production downtime, significantly affecting the company&#8217;s key business operations.<\/p>\n<h2>Steps to Prevention &#038; Mitigation<\/h2>\n<p>Organizations are advised to take immediate action to mitigate vulnerability exposure.<\/p>\n<p>This includes promptly applying the Veeam patches, always using the latest software versions, and frequently changing and strengthening user credentials.<\/p>\n<p>Furthermore, companies should employ multi-factor authentication (MFA) wherever possible, conduct regular vulnerability assessments, and ensure their incident response plan is updated.<\/p>\n<h2>Conclusion<\/h2>\n<p>The exploitation of the Veeam vulnerability to spread Akira and Fog ransomware serves as a stark reminder of the evolving nature of cybersecurity threats and the need for continuous vigilance and effective cyber hygiene practices across all sectors.<\/p>\n<h2>Follow-Up Reading<\/h2>\n<ul>\n<li><a href=\"https:\/\/www.veeam.com\/kb3145\">Veeam Security Advisory about CVE-2024-40711<\/a><\/li>\n<li><a href=\"https:\/\/www.sophos.com\/en-us\/medialibrary\/PDFs\/factsheets\/sophoslabs-uncut-akira-ransomware.pdf\">Sophos&#8217;s Report on Akira Ransomware<\/a><\/li>\n<li><a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-40711\">Detailed Information on CVE-2024-40711<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Common Vulnerability Scoring System (CVSS), is a critical privilege escalation vulnerability that allows remote attackers<\/p>\n","protected":false},"author":1,"featured_media":2679,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"pmpro_default_level":"","_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[2,5],"tags":[],"class_list":["post-2678","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","category-news","pmpro-has-access"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/posts\/2678","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/comments?post=2678"}],"version-history":[{"count":1,"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/posts\/2678\/revisions"}],"predecessor-version":[{"id":2684,"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/posts\/2678\/revisions\/2684"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/media\/2679"}],"wp:attachment":[{"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/media?parent=2678"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/categories?post=2678"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/tags?post=2678"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}