Vendor
Veeam
- First Reported
- Sep 8, 2025
- Latest Reported
- Jun 29, 2026
Reported Context (5)
- They engaged in extensive credential harvesting, utilizing wbadmin.exe to extract the NTDS.dit Active Directory database and executing custom PowerShell scripts to dump and decrypt Veeam credentials via DPAPI. Bing SEO Poisoning Led to BumbleBee, AdaptixC2 and Akira Ransomware Intrusions
- 2026, Gambit Security published a technical report documenting SQL Server deletion, VM partition wipes, Veeam backup destruction, and file system damage across four victim environments, but deliberately withheld the Exposed Staging Server Reveals Data from Ababil of Minab Campaign, Including LA Metro Records
- In particular, the RDP bitmap cache of the beachhead host shows the threat actor opening the Veeam Backup & Replication console. Lynx Ransomware Attack Began with Compromised RDP Credentials
- Veeam-Get-Creds Lunar Spider Intrusion Used Tax-Themed JavaScript to Maintain Access for Nearly Two Months
- On a backup server, they executed a PowerShell script designed to retrieve Veeam credentials. DFIR Report Links Intrusion to Tools Used by Three Ransomware Groups
CVE (1)
Malware (13)
People (17)
Threat Actors (7)
MITRE ATT&CK (75)
Vendors (12)
Products (20)
Tools (29)
Industries (6)
Countries (14)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.