Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Description

Frag is a ransomware group that emerged in late 2024, exploiting a critical Veeam Backup & Replication vulnerability (CVE-2024-40711) to compromise targets in industrial sectors, with blockchain analysis linking it to a shared wallet cluster with the Akira group. Known victims: 30

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Frag is a ransomware group that emerged in late 2024, exploiting vulnerabilities in Veeam Backup & Replication (CVE-2024-40711) to target industrial sectors. They are linked to the Akira group through blockchain analysis and primarily seek financial gain through加密勒索软件攻击.

Goals & Targeting

The primary goals of the frag group align with financial gain through ransomware activities. They target industrial sectors, which often have critical infrastructure with less frequent patching cycles, making them lucrative targets. By exploiting Veeam vulnerabilities, they can infiltrate networks and deploy encryption-based attacks to maximize payout potential.

Enhanced Description

Frag represents a new ransomware group that surfaced in September 2024, leveraging a critical vulnerability in Veeam Backup & Replication (CVE-2024-40711) to breach industrial sector targets. Their operations demonstrate moderate technical sophistication, with a focus on encrypting victim systems and demanding ransoms. The group's ties to Akira suggest potential collaborative or affiliate relationships within the cybercrime ecosystem. Frag has shown persistence across multiple months, targeting sectors that likely offer high-value assets for extortion. Their campaign patterns are still emerging, but early evidence indicates a methodical approach to compromising backdoor access and encrypting systems.

Key Capabilities

  • Exploitation of CVE-2024-40711 in Veeam Backup & Replication
  • Ransomware deployment for financial gain
  • Targeting industrial sectors via network infiltration

MITRE ATT&CK Tactics

Initial Access
Exfiltration/Implantations

ATT&CK Techniques

T1203.002
T1566.001

Campaigns & Victims

Frag has conducted campaigns targeting industrial sectors, utilizing sophisticated methods to compromise systems through Veeam vulnerabilities. Their relatively short operational timeline suggests they are still establishing their presence but have demonstrated capability in executing加密勒索软件攻击. Their known victims include entities whose operations depend on robust backup solutions.

IOC Patterns

  • Email-based communication from frag-blog@proton.me and frag-blog@tutamail.com

Recommended Actions

  • Patch Veeam Backup & Replication to address CVE-2024-40711
  • Implement multi-factor authentication (MFA) for sensitive systems
  • Monitor network traffic for异常加密活动或可疑通信

Suggested Tags

ransomware
criminal

Confidence Assessment

The group's operations are relatively well-documented, with clear evidence of exploitation techniques and targeting patterns. However, additional details about their specific tools and exact campaign history remain limited. Confidence in current intelligence is moderate due to the group's recent emergence.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

8

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
ransomware
criminal

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Sep 24, 2024
Last Seen
Jun 12, 2025
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.