Menu

  • Alerts
  • Incidents
  • News
  • APTs
  • Cyber Decoded
  • Cyber Hygiene
  • Cyber Review
  • Cyber Tips
  • Definitions
  • Malware
  • Threat Actors
  • Tutorials

Useful Tools

  • Password generator
  • Report an incident
  • Report to authorities
No Result
View All Result
CTF Hack Havoc
CyberMaterial
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
Hall of Hacks
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
No Result
View All Result
Hall of Hacks
CyberMaterial
No Result
View All Result
Home Alerts

FIN7 Exploits Unpatched Veeam Instances

April 27, 2023
Reading Time: 2 mins read
in Alerts

 

 

Russian cybercrime group FIN7, also known as Anunak and Carbanak, has been found to be exploiting unpatched instances of Veeam Backup & Replication in recent attacks. FIN7 is primarily focused on credit card information theft and is believed to have numerous sub-groups operating under its umbrella.

The group has been active since at least 2015 and has been linked to other threat actors that have transitioned to ransomware, including REvil, DarkSide, BlackMatter, Alphv, and Black Basta.

WithSecure, a cybersecurity company, caught FIN7 attacks at the end of March 2023 that exploited internet-facing servers running Veeam Backup & Replication software to execute payloads on the compromised environment.

The cybersecurity firm observed a Veeam Backup process executing a shell command to download and execute a PowerShell script that turned out to be the Powertrash in-memory dropper known to be used by FIN7. The dropper was used to drop Diceloader, a backdoor that enables attackers to perform various post-exploitation operations and has been linked to FIN7 before.

WithSecure identified suspicious activity targeting the exploited Veeam backup instances days before payloads were dropped, likely to probe and identify vulnerable servers.

The threat actor was seen performing network reconnaissance, stealing information from the Veeam backup database, exfiltrating stored credentials, achieving persistence for the Diceloader backdoor, and moving laterally using the stolen credentials. WithSecure notes that they have so far identified two instances of such attacks conducted by FIN7, which were likely part of a larger campaign.

CVE-2023-27532 (CVSS score of 7.5) was disclosed and patched in early March. Successful exploitation of the bug allows an attacker to obtain encrypted credentials that are stored in the configuration database.

Veeam Backup & Replication versions 12 and 11a have been released to address the vulnerability, and organizations are advised to update their Backup & Replication instances as soon as possible. Vulnerabilities in Veeam’s product have been exploited in previous attacks.

Reference:
  • FIN7 tradecraft seen in attacks against Veeam backup servers

Tags: April 2023Cyber AlertCyber Alerts 2023FIN7RansomwareVeeam Backup
ADVERTISEMENT

Related Posts

Microsoft Defender Bug Allows SYSTEM Access

Uncanny Automator Bug Risks WordPress Sites

May 14, 2025
Microsoft Defender Bug Allows SYSTEM Access

Devs Hit By PyPI Solana Token Secret Theft

May 14, 2025
Microsoft Defender Bug Allows SYSTEM Access

Microsoft Defender Bug Allows SYSTEM Access

May 14, 2025
Apple Fixes Critical Bugs in iOS and MacOS

Hackers Exploit Output Messenger Zero-Day

May 13, 2025
Apple Fixes Critical Bugs in iOS and MacOS

ASUS Fixes Critical Flaws in DriverHub

May 13, 2025
Apple Fixes Critical Bugs in iOS and MacOS

Apple Fixes Critical Bugs in iOS and MacOS

May 13, 2025

Latest Alerts

Microsoft Defender Bug Allows SYSTEM Access

Uncanny Automator Bug Risks WordPress Sites

Devs Hit By PyPI Solana Token Secret Theft

Hackers Exploit Output Messenger Zero-Day

ASUS Fixes Critical Flaws in DriverHub

Apple Fixes Critical Bugs in iOS and MacOS

Subscribe to our newsletter

    Latest Incidents

    Alabama Cybersecurity Event Hits Services

    Andy Frain Data Breach Impacts 100k People

    Hong Kong DSC Hit By Ransomware Attack

    Alleged Steam Breach Exposes 89M Records

    Ulhasnagar Municipal Corporation Hacked

    Madison County Iowa Systems Disrupted

    CyberMaterial Logo
    • About Us
    • Contact Us
    • Jobs
    • Legal and Privacy Policy
    • Site Map

    © 2025 | CyberMaterial | All rights reserved

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In

    Add New Playlist

    No Result
    View All Result
    • Alerts
    • Incidents
    • News
    • Cyber Decoded
    • Cyber Hygiene
    • Cyber Review
    • Definitions
    • Malware
    • Cyber Tips
    • Tutorials
    • Advanced Persistent Threats
    • Threat Actors
    • Report an incident
    • Password Generator
    • About Us
    • Contact Us
    • Advertise with us

    Copyright © 2025 CyberMaterial