Sophos X-Ops reported that attackers in threat cluster STAC 5881 again exploited Veeam backup servers through CVE-2024-40711 after first obtaining access through compromised VPN appliances. The activity follows earlier intrusions tied to Akira and Fog ransomware, but the latest case used a previously undocumented ransomware family called Frag. During the intrusion, the attackers created local administrator accounts named point and point2, repeating tradecraft seen in prior incidents.
Frag is a command-line ransomware that requires an encryption-percentage parameter, can be directed at specific files or directories, and appends the .frag extension to encrypted data. Sophos said its CryptoGuard protection blocked the encryption attempt and that detection for the Frag binary has since been added. Sophos and Agger Labs said the operation shares tactical similarities with actors linked to Akira and Fog, indicating that a new ransomware operator may be reusing established access methods and post-compromise techniques against Veeam environments.

See which actors are running it and whether you're in range.
4 events from the most recent confirmed update back to the earliest known activity.
Sophos and Agger Labs reported tactical similarities between the actor behind Frag and actors associated with Akira and Fog. They said the overlap may indicate the emergence of a new ransomware operator using familiar tradecraft.
Sophos said its CryptoGuard feature blocked the Frag ransomware in the observed incident. The company also stated that a detection for the Frag binary has since been added.
In a more recent case, Sophos observed the same cluster using similar tradecraft but deploying a previously undocumented ransomware family named Frag instead of Akira or Fog. The attackers again created a local administrator account named "point" and also created a second account named "point2."
Sophos X-Ops said threat cluster STAC 5881 had previously exploited Veeam backup servers via CVE-2024-40711 after access through compromised VPN appliances. Those earlier incidents resulted in deployment of Akira or Fog ransomware.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.