ALPHV ransomware leverages Veritas Backup Exec vulnerabilities for entry

1 min read
Source: BleepingComputer
ALPHV ransomware leverages Veritas Backup Exec vulnerabilities for entry
Photo: BleepingComputer
TL;DR Summary

The ALPHV ransomware affiliate, UNC4466, has been observed exploiting three vulnerabilities in Veritas Backup Exec to gain initial access to target networks. The flaws, which were disclosed in March 2021, allow for arbitrary file access, remote unauthorized access, and arbitrary command execution. Despite a fix being released over two years ago, many endpoints remain vulnerable. UNC4466 uses publicly-available tools like Metasploit and SOCKS5 tunneling to communicate with the command and control server and evade detection. Mandiant provides guidance for defenders to detect and mitigate these attacks.

Share this article

Reading Insights

Total Reads

0

Unique Readers

0

Time Saved

2 min

vs 3 min read

Condensed

83%

51586 words

Want the full story? Read the original article

Read on BleepingComputer