Threat Advisory

FIN7 Attackers Caught Exploiting Recent Veeam Vulnerability

Threat: Vulnerability
Criticality: High
[subscribe_to_unlock_form]

Summary:

The group known as FIN7, also called Anunak and Carbanak, has been active since 2015 and appears to be financially motivated, with a primary focus on stealing credit card information. It is believed that FIN7 may consist of multiple sub-groups operating under the same umbrella. In recent years, some of the threat actors who have been associated with FIN7's activities have shifted their focus to ransomware. These groups include REvil, DarkSide, BlackMatter, Alphv, and Black Basta. In March 2023, WithSecure detected FIN7 attacks targeting internet-facing servers that were running Veeam Backup & Replication software. The attacks were successful in deploying payloads onto the compromised systems.[/subscribe_to_unlock_form]

Summary:

The group known as FIN7, also called Anunak and Carbanak, has been active since 2015 and appears to be financially motivated, with a primary focus on stealing credit card information. It is believed that FIN7 may consist of multiple sub-groups operating under the same umbrella. In recent years, some of the threat actors who have been associated with FIN7's activities have shifted their focus to ransomware. These groups include REvil, DarkSide, BlackMatter, Alphv, and Black Basta. In March 2023, WithSecure detected FIN7 attacks targeting internet-facing servers that were running Veeam Backup & Replication software. The attacks were successful in deploying payloads onto the compromised systems.[emaillocker id="1283"]

During the attack, a Veeam Backup process was observed executing a shell command to download and run a PowerShell script. The PowerShell script was later identified as the Powertrash in-memory dropper, which is known to be used by FIN7. Following the execution of the Powertrash dropper, the attackers were able to drop a backdoor called Diceloader (also known as Lizar). This backdoor allows the attackers to carry out post-exploitation activities and has been previously associated with FIN7. The specific technique employed by the attackers to execute the initial shell commands is not known. However, it is believed that the attackers may have exploited a recently patched vulnerability in Veeam Backup & Replication (CVE-2023-27532), which could have granted them unauthorized access to a Veeam Backup & Replication instance.

It has been stated that if the vulnerability is successfully exploited, an attacker can gain access to encrypted credentials stored in the configuration database. However, other security experts, who have released a proof-of-concept, claim that the flaw may allow attackers to obtain cleartext credentials instead.

Recommendations:

We strongly recommend that you upgrade your Veeam Backup & Replication to version 12 (build 12.0.0.1420 P20230223) and 11a (build 11.0.1.1261 P20230227).

References:

The following reports contain further technical details:

https://www.securityweek.com/fin7-hackers-caught-exploiting-recent-veeam-vulnerability/

[/emaillocker]
crossmenu