Ransomware gang exploiting unpatched Veeam backup products

pinkeyes – stock.adobe.com

Cyber criminals with links to multiple virulent ransomware strains are exploiting a recently disclosed vulnerability in Veeam’s Backup & Replication product, threat analysts have warned

Alex Scroxton

By

Published: 26 Apr 2023 12:04

Researchers at WithSecure have issued an alert after uncovering evidence that a notorious cyber criminal gang is exploiting a recently disclosed vulnerability in Veeam Backup & Replication data backup and recovery software to access its victims’ networks.

Tracked as CVE-2023-27532, the Veeam vulnerability was first published on 7 March 2023. It enables an unauthenticated user who has accessed the backup infrastructure network perimeter to get their hands on encrypted credentials stored in the configuration database, which may ultimately lead to them gaining access to the backup infrastructure hosts.

It is classified as a high-severity bug and carries a CVSS v3 score of 7.5. It exists in the Veeam.Backup.Service.exe process of Veaam Backup & Replication, Veeam Cloud Connect, Veeam Cloud Connect for the Enterprise and Veeam Backup & Replication Community Edition.

“WithSecure Intelligence identified attacks which occurred in late March 2023 against internet-facing servers running Veeam Backup & Replication software,” wrote WithSecure analysts Neeraj Singh and Mohammad Kazem Hassan Nejad.

“Our research indicates with high confidence that the intrusion set used in these attacks is consistent with activities attributed to the FIN7 activity group. It is likely that initial access and execution was achieved through a recently patched Veeam Backup & Replication vulnerability, CVE-2023-27532,” they explained.

“Our research indicates with high confidence that the intrusion set used in these attacks is consistent with activities attributed to the FIN7 activity group. It is likely that initial access and execution was achieved through a recently patched Veeam Backup & Replication vulnerability, CVE-2023-27532”
Neeraj Singh and Mohammad Kazem Hassan Nejad, WithSecure

FIN7 is a prolific and dangerous financially motivated operator that has deployed multiple strains of ransomware in its attacks – including BlackCat/ALPHV, BlackMatter, DarkSide and, at one time, REvil – after pivoting to extortion from payment card data theft about three years ago.

The group may have links to multiple recent high-profile cyber attacks, including the developing heist on UK public sector outsourcer Capita, payments systems giant NCR and Munster Technological University in Ireland. There is no indication at the time of writing that any of these intrusions involved exploitation of the Veeam compromise.

On 28 March 2023, Singh and Nejad said they saw activity across multiple internet-facing servers running Veeam Backup & Replication, in which a SQL server process related to the backup instance executed a shell command, which performed in-memory download and execution of a PowerShell script.

FIN7 is known to be particularly fond of the PowerShell scripting language – Mandiant once described PowerShell as the gang’s “love language” – and on this occasion, all instances of the PowerShell scripts seen were Powertrash, an obfuscated loader directly attributed to FIN7.

Powertrash itself is used to execute various payloads, including but not limited to old “favourites” such as the Carbanak malware, with which FIN7 originally made its name, and of course the ubiquitous Cobalt Strike, but this time round they used Diceloader (aka Lizar) to gain a foothold.

Singh and Nejad said that while the exact method FIN7 used to invoke the initial shell command was unknown, it was likely achieved via the Veeam bug, based on a number of factors:

  • All affected servers had TCP open port 9401 – used for communication with the Veeam Backup Service over SSL exposed to the internet – and network activity with external IP addresses was seen over said port right before the shell command was invoked.
  • The vulnerability was patched a few weeks prior, and exploitation of it requires access to port 9401.
  • None of the affected servers had been patched against the Veeam bug.
  • A proof-of-concept exploit was circulating on 23 March, which contains the same execution chain as seen in this campaign.

WithSecure’s observers said they also saw suspicious activity on the affected servers on 24 March, which they believe may have been evidence that FIN7 was performing large-scale vulnerability scanning to find at-risk servers.

Once inside, they said, FIN7 used a series of commands and custom scripts to begin to gather data on their targets, and executed a series of SQL commands to steal information from the Veeam backup database, as well as retrieving stored credentials and using them to attempt lateral movement.

Ultimately, it is possible that these footholds would have developed into ransomware hits, and with absent patching or widespread awareness, some may yet do so.

However, according to Singh and Nejad, the probable rarity of Veeam backup servers with TCP port 9401 publicly exposed means the scope of the incident is likely limited.

The vulnerability is resolved by builds 12 (12.0.0.1420 P20230223) and 11a (11.0.1.1261 P20230227) of Veeam Backup & Replication. As a temporary workaround, users operating an all-in-one Veeam appliance with no remote backup infrastructure components can block external connections to Port TCP 9401 in the backup server firewall until they can install the patch.

Read more on Hackers and cybercrime prevention

Read More
Larisa Noren

Latest

Mentalist Oz Pearlman Will Get Inside Trump’s Mind at the White House Correspondents’ Dinner

Typically, the White House Correspondents’ Dinner features a comedian for its star act. In years past, the journalists, executives, agents, and miscellaneous members of the DC establishment have gathered at the Washington Hilton to hear speeches from the head of the correspondents’ association and the president. Then a comedian gets up to properly skewer the

David Pollack Reflects on Being Laid Off From ESPN College GameDay

Moving from the Saturday morning spotlight to a home studio was a major shift for one of the most decorated defensive players in college football history. David Pollack, the former Georgia Bulldog and longtime ESPN mainstay, recently shared his perspective on the day his 13-year tenure at the network came to an abrupt end. Appearing

Star High School Football Player Shot and Killed in Texas

Star High School Football Player Shot and Killed in Texas A Lancaster High School football player was shot and killed during an off-campus shooting this week. Myers Anthony, a 16-year-old football star at Lancaster High School in Lancaster. The shooting is still being investigated as a homicide and appears to be an isolated incident. Anthony

New Orleans Saints News, April 16: Could Arvell Reese fall to the Saints?

Skip to main content Here are today’s Saints news links Apr 16, 2026, 12:30 PM UTC Welcome to today’s roundup of New Orleans Saints and NFL news! Some Saints players are showing up off the football field. A worrying trend. Without a doubt for the Saints. New Orleans Saints News Apr 15 New Orleans Saints

Newsletter

Don't miss

Mentalist Oz Pearlman Will Get Inside Trump’s Mind at the White House Correspondents’ Dinner

Typically, the White House Correspondents’ Dinner features a comedian for its star act. In years past, the journalists, executives, agents, and miscellaneous members of the DC establishment have gathered at the Washington Hilton to hear speeches from the head of the correspondents’ association and the president. Then a comedian gets up to properly skewer the

David Pollack Reflects on Being Laid Off From ESPN College GameDay

Moving from the Saturday morning spotlight to a home studio was a major shift for one of the most decorated defensive players in college football history. David Pollack, the former Georgia Bulldog and longtime ESPN mainstay, recently shared his perspective on the day his 13-year tenure at the network came to an abrupt end. Appearing

Star High School Football Player Shot and Killed in Texas

Star High School Football Player Shot and Killed in Texas A Lancaster High School football player was shot and killed during an off-campus shooting this week. Myers Anthony, a 16-year-old football star at Lancaster High School in Lancaster. The shooting is still being investigated as a homicide and appears to be an isolated incident. Anthony

New Orleans Saints News, April 16: Could Arvell Reese fall to the Saints?

Skip to main content Here are today’s Saints news links Apr 16, 2026, 12:30 PM UTC Welcome to today’s roundup of New Orleans Saints and NFL news! Some Saints players are showing up off the football field. A worrying trend. Without a doubt for the Saints. New Orleans Saints News Apr 15 New Orleans Saints

How NFL Prospects Can Build a Winning Football Resume

How NFL Prospects Can Build a Winning Football Resume For serious football players, a clean, well-structured football resume example can help turn game film into something a coach, scout, recruiter, or personnel staffer can scan fast and actually use. The competition is brutal at every level, with only 1.4% of NCAA football players drafted into the NFL

Family Business? Tee Grizzley Reacts After His Mom Accuses Him Of Leaving Her To Struggle (PHOTOS)

Y’all… it looks like some family tension might be brewing behind the scenes involving Tee Grizzley and his mom. What seemed like a regular social media post quickly turned into something deeper. And now, folks are side-eyeing the situation and wondering what’s really going on. RELATED: Tee Grizzley Shares A Message For Artists After His

SoE necessary but not sufficient, business leaders say

PE­TER CHRISTO­PHER Se­nior Mul­ti­me­dia Re­porter pe­ter.christo­pher@guardian.co.tt Heavy hand­ed but nec­es­sary giv­en the state of crime in T&T. This was a com­mon as­sess­ment from var­i­ous busi­ness groups when asked for their per­spec­tive on the lat­est de­c­la­ra­tion of a state of emer­gency in the coun­try. The T&T Cham­ber of In­dus­try and Com­merce, in a re­leased is­sued yes­ter­day

The Big Business of Carolyn Bessette-Kennedy

Can a nine-episode limited series really impact an entire season of shopping trends? Today brands are experiencing—and chasing—the “Carolyn Bessette-Kennedy effect” as a result of Ryan Murphy’s Love Story. And in many cases, it’s more pervasive than they could have prepared for. The FX series, based on the relationship between John F. Kennedy Jr. and