Frag is a ransomware group that emerged in late 2024, exploiting a critical Veeam Backup & Replication vulnerability (CVE-2024-40711) to compromise targets in industrial sectors, with blockchain analysis linking it to a shared wallet cluster with the Akira group. Known victims: 30
Objectives
Executive Summary
Frag is a ransomware group that emerged in late 2024, exploiting vulnerabilities in Veeam Backup & Replication (CVE-2024-40711) to target industrial sectors. They are linked to the Akira group through blockchain analysis and primarily seek financial gain through加密勒索软件攻击.
Goals & Targeting
The primary goals of the frag group align with financial gain through ransomware activities. They target industrial sectors, which often have critical infrastructure with less frequent patching cycles, making them lucrative targets. By exploiting Veeam vulnerabilities, they can infiltrate networks and deploy encryption-based attacks to maximize payout potential.
Enhanced Description
Frag represents a new ransomware group that surfaced in September 2024, leveraging a critical vulnerability in Veeam Backup & Replication (CVE-2024-40711) to breach industrial sector targets. Their operations demonstrate moderate technical sophistication, with a focus on encrypting victim systems and demanding ransoms. The group's ties to Akira suggest potential collaborative or affiliate relationships within the cybercrime ecosystem. Frag has shown persistence across multiple months, targeting sectors that likely offer high-value assets for extortion. Their campaign patterns are still emerging, but early evidence indicates a methodical approach to compromising backdoor access and encrypting systems.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Campaigns & Victims
Frag has conducted campaigns targeting industrial sectors, utilizing sophisticated methods to compromise systems through Veeam vulnerabilities. Their relatively short operational timeline suggests they are still establishing their presence but have demonstrated capability in executing加密勒索软件攻击. Their known victims include entities whose operations depend on robust backup solutions.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The group's operations are relatively well-documented, with clear evidence of exploitation techniques and targeting patterns. However, additional details about their specific tools and exact campaign history remain limited. Confidence in current intelligence is moderate due to the group's recent emergence.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
8
IOCs
0
Observed Data
0
Tactics