A now-patched security flaw in Veeam Backup & Replication softwareis being exploited by a nascent ransomware known as EstateRansomware.
See also: Ransomware groups turn to defensive evasion

Singapore-based Group-IB, which discovered the malicious agent in early April 2024, said that the modus operandi involved exploiting CVE-2023-27532 (CVSS score: 7.5) to carry out the malicious activities.
Initial access to the target environment is said to have been facilitated through a Fortinet FortiGate SSL VPN firewall appliance , using a dormant account .
“ The malicious agent moved laterally from the FortiGate firewall through the SSL VPN service to access the redirect server ,” security researcher Yeo Zi Wei said in a recently published analysis.
The EstateRansomware team then proceeded to create RDP connections from the firewall to the Veeam failover server, followed by the deployment of a persistent backdoor named “svchost.exe” that runs daily via a scheduled task.
Subsequent network access was achieved using the backdoor to evade detection. The backdoor's primary responsibility is to connect to a server via HTTP and execute arbitrary commands issued by the attacker.
See also: Avast: Decryption tool for DoNex, Muse, DarkRace ransomware
Group-IB said it observed the EstateRansomware group exploiting the Veeam flaw CVE-2023-27532 with the aim of enabling xp_cmdshell on the backup server and creating a fake user account named “ VeeamBkp ,” while also conducting discovery, enumeration, and credential harvesting activities using tools such as NetScan, AdFind , and NitSoft using the new account.

The attack culminated in the deployment of ransomware, but not before taking steps to degrade defenses and move laterally from the AD server to all other servers and workstations using compromised domain accounts.
The revelation comes as Cisco Talos said most ransomware gangs prioritize establishing initial access by exploiting security flaws in public applications, phishing , or compromising valid accounts and bypassing defenses in their attack chains.
The double extortion model of data extraction before file encryption further led to custom tools developed by the actors (e.g. Exmatter, Exbyte, and StealBit) to send the confidential information to an infrastructure controlled by the adversary.
See also: STORMOUS Ransomware claims HITC Telecom breach
Ransomware groups are organized cybercriminal entities that develop ransomware to extort money from individuals, businesses, and even government institutions, such as EstateRansomware that compromised Veeam software. These groups design malware that encrypts a victim’s data, making it inaccessible until a ransom is paid, often in cryptocurrency to maintain anonymity. Particularly sophisticated, these groups often operate with a high level of professionalism, using strategies such as double blackmail, where they threaten to leak stolen data if the ransom is not paid. Prominent ransomware groups such as REvil, Conti , and DarkSide have made headlines for their high-profile attacks and the significant financial impact on their targets.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: thehackernews
