Eamfo is an information-stealing malware used in BlackCat/ALPHV (also tracked by Symantec as Noberus) ransomware intrusions. It is designed to steal credentials stored by Veeam backup software, including credentials that may provide access to domain controllers and cloud services, thereby facilitating privilege escalation and lateral movement. Reported behavior includes connecting to the Veeam SQL database, executing the query select [user_name],[password],[description] FROM [VeeamBackup].[dbo].[Credentials] to retrieve stored credential data, decrypting the extracted credentials, and displaying them to the operator. Symantec reported Eamfo in the context of BlackCat’s evolving tooling for double-extortion operations. Similar Veeam-focused credential theft has also been noted in reporting on Monti, Yanluowang, and LockBit.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Information-stealing malware focused on extracting credentials stored by Veeam backup software; used to facilitate privilege escalation and lateral movement in intrusions.
Credential-stealing malware that queries the Veeam SQL database to extract stored backup credentials (e.g., for domain controllers/cloud services), decrypts them, and presents them to the operator to enable deeper access and lateral movement.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.