Researchers at WithSecure cybersecurity firm have seen two malware attacks against Veeam Backup and Replication servers believed to be initiated by cybercrime group FIN7, also known as Carbon Spider, which has also been linked to Darkside, BlackMatter, and BlackCat/ALPHV ransomware variants.
The WithSecure investigators believe that the attacks may be part of a larger campaign, but that the scope of the attack is limited. Nonetheless, because of the sophistication of FIN7, WithSecure recommends that companies using Veeam’s solutions follow Veeam’s recommendations and guidelines to patch and configure their backup servers against a recently discovered vulnerability as outlined in Kb4424: CVE-2023-27532 and watch for signs of compromise.