Product
Veeam
- First Reported
- Sep 8, 2025
- Latest Reported
- Jun 29, 2026
Reported Context (3)
- They engaged in extensive credential harvesting, utilizing wbadmin.exe to extract the NTDS.dit Active Directory database and executing custom PowerShell scripts to dump and decrypt Veeam credentials via DPAPI. Bing SEO Poisoning Led to BumbleBee, AdaptixC2 and Akira Ransomware Intrusions
- 2026, Gambit Security published a technical report documenting SQL Server deletion, VM partition wipes, Veeam backup destruction, and file system damage across four victim environments, but deliberately withheld the Exposed Staging Server Reveals Data from Ababil of Minab Campaign, Including LA Metro Records
- On a backup server, they executed a PowerShell script designed to retrieve Veeam credentials. DFIR Report Links Intrusion to Tools Used by Three Ransomware Groups
Malware (8)
People (12)
Threat Actors (6)
MITRE ATT&CK (57)
Vendors (11)
Products (13)
Tools (22)
Industries (6)
Countries (6)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.