While the vulnerability CVE-2023-27532 was made public in March 2023 and subsequently patched by Veeam for versions 12/11a and later for Veeam Backup & Replication software, Group-IB’s Digital Forensics and Incident Response (DFIR) team recently observed a notable incident related to this vulnerability. Author: AlienVault
Related Tags:
svhost
FortiGate
CVE-2023-27532
veeam
VPN
T1555
T1133
ransomware
T1078
Associated Indicators:
2C56E9BEEA9F0801E0110A7DC5549B4FA0661362
107EC3A7ED7AD908774AD18E3E03D4B999D4690C
5E460A517F0579B831B09EC99EF158AC0DD3D4FA
149.28.106.252
149.28.99.61