HomeSecurityEstateRansomware exploits vulnerability in Veeam software

EstateRansomware exploits vulnerability in Veeam software

A now-patched security flaw in Veeam Backup & Replication softwareis being exploited by a nascent ransomware known as EstateRansomware.

See also: Ransomware groups turn to defensive evasion

EstateRansomware Veeam

Singapore-based Group-IB, which discovered the malicious agent in early April 2024, said that the modus operandi involved exploiting CVE-2023-27532 (CVSS score: 7.5) to carry out the malicious activities.

Initial access to the target environment is said to have been facilitated through a Fortinet FortiGate SSL VPN firewall appliance , using a dormant account .

The malicious agent moved laterally from the FortiGate firewall through the SSL VPN service to access the redirect server ,” security researcher Yeo Zi Wei said in a recently published analysis.

The EstateRansomware team then proceeded to create RDP connections from the firewall to the Veeam failover server, followed by the deployment of a persistent backdoor named “svchost.exe” that runs daily via a scheduled task.

Subsequent network access was achieved using the backdoor to evade detection. The backdoor's primary responsibility is to connect to a server via HTTP and execute arbitrary commands issued by the attacker.

See also: Avast: Decryption tool for DoNex, Muse, DarkRace ransomware

Group-IB said it observed the EstateRansomware group exploiting the Veeam flaw CVE-2023-27532 with the aim of enabling xp_cmdshell on the backup server and creating a fake user account named “ VeeamBkp ,” while also conducting discovery, enumeration, and credential harvesting activities using tools such as NetScan, AdFind , and NitSoft using the new account.

EstateRansomware exploits vulnerability in Veeam software

The attack culminated in the deployment of ransomware, but not before taking steps to degrade defenses and move laterally from the AD server to all other servers and workstations using compromised domain accounts.

The revelation comes as Cisco Talos said most ransomware gangs prioritize establishing initial access by exploiting security flaws in public applications, phishing , or compromising valid accounts and bypassing defenses in their attack chains.

The double extortion model of data extraction before file encryption further led to custom tools developed by the actors (e.g. Exmatter, Exbyte, and StealBit) to send the confidential information to an infrastructure controlled by the adversary.

See also: STORMOUS Ransomware claims HITC Telecom breach

Ransomware groups are organized cybercriminal entities that develop ransomware to extort money from individuals, businesses, and even government institutions, such as EstateRansomware that compromised Veeam software. These groups design malware that encrypts a victim’s data, making it inaccessible until a ransom is paid, often in cryptocurrency to maintain anonymity. Particularly sophisticated, these groups often operate with a high level of professionalism, using strategies such as double blackmail, where they threaten to leak stolen data if the ransom is not paid. Prominent ransomware groups such as REvil, Conti , and DarkSide have made headlines for their high-profile attacks and the significant financial impact on their targets.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Source: thehackernews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS