Multiple ransomware operations have exploited a critical Veeam Backup & Replication weakness, including CVE-2023-27532, to gain unauthorized access and deploy malware in victim environments. Reporting tied the activity to Akira, Fog, and later Frag ransomware, with attackers abusing exposed Veeam infrastructure to retrieve credentials and move deeper into networks. Rapid7's analysis of the flaw showed it could allow access to sensitive configuration data, making Veeam servers a high-value target for follow-on compromise.
Additional reporting said some intrusions also involved compromised VPN credentials, combining stolen remote-access accounts with exploitation of Veeam systems to establish footholds and launch ransomware. The incidents show attackers repeatedly targeting backup infrastructure not only to encrypt production systems but also to undermine recovery options, reinforcing the need to patch internet-exposed Veeam servers, restrict administrative access, and protect stored credentials tied to backup and remote-access platforms.

See which actors are running it and whether you're in range.
4 events from the most recent confirmed update back to the earliest known activity.
Sophos later reported that the same Veeam exploit was observed again in attacks involving a newer ransomware family called Frag. This showed continued reuse of the Veeam attack path by additional ransomware operators.
TechRadar reported that threat actors were combining compromised VPN credentials with exploitation of the Veeam vulnerability to deploy malware. This added operational detail on intrusion chains beyond the earlier ransomware reporting.
By early October 2024, reporting indicated that the Akira and Fog ransomware groups were exploiting a critical Veeam remote code execution flaw in real-world attacks. The activity showed the vulnerability had moved from disclosure into active ransomware operations.
Rapid7 published analysis of CVE-2023-27532, a Veeam Backup & Replication vulnerability that later became associated with ransomware intrusion activity. This marks the earliest referenced public documentation of the flaw in the provided sources.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
4 references tracked. Mallory keeps watching after this page renders.
news.sophos.com
Open sourcetechradar.com
Open sourcebleepingcomputer.com
Open sourceattackerkb.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.