STAC 5881 is a threat activity cluster associated with ransomware intrusions that begin with access through compromised VPN appliances and subsequent exploitation of CVE-2024-40711 on Veeam backup servers. The cluster has been observed using the Veeam flaw to create new local administrator accounts and then proceeding to ransomware deployment. Reported outcomes linked to this cluster include Akira ransomware, Fog ransomware, and a later case involving the previously undocumented Frag ransomware family. The cluster’s tradecraft indicates a focused post-compromise workflow centered on abusing edge-access infrastructure for initial access, exploiting exposed backup-management infrastructure, and establishing privileged local access before ransomware execution. In the Frag-linked case, the operators repeated the same pattern and created multiple local administrator accounts. Frag has been described as a command-line ransomware variant that supports selective encryption through operator-supplied parameters, including the percentage of file encryption and targeting of specific files or directories. STAC 5881 appears to represent a recurring intrusion pattern rather than a formally attributed nation-state group. Its observed behavior aligns with financially motivated ransomware operations, and its tactics overlap with activity associated with Akira and Fog operators. Available information supports tracking STAC 5881 as a ransomware-focused cluster using consistent access and privilege-establishment techniques across multiple incidents.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named threat activity cluster exploiting CVE-2024-40711 in Veeam backup servers after gaining access via compromised VPN appliances, creating local administrator accounts, and leading in some cases to ransomware deployment including Akira, Fog, and later Frag.
A named threat activity cluster exploiting CVE-2024-40711 on Veeam backup servers after gaining access via compromised VPN appliances, creating local administrator accounts, and in some cases deploying Akira, Fog, or the newly observed Frag ransomware.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.