Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
MalwareRansomwareExploits 1 CVE

Frag

Frag is a previously undocumented ransomware family observed by Sophos X-Ops in late 2024 and associated with threat activity cluster STAC 5881. In the reported incidents, the operators gained initial access via compromised VPN appliances and then exploited Veeam Backup & Replication remote code execution vulnerability CVE-2024-40711 on backup servers. The same cluster had previously deployed Akira and Fog ransomware, and Sophos and Agger Labs noted that Frag-related tradecraft overlaps with tactics seen in Akira- and Fog-associated activity, suggesting either a new ransomware actor using similar methods or operational overlap. In the Frag case, the attackers used the Veeam flaw to create local administrator accounts named "point" and "point2". Frag is a command-line ransomware that requires a parameter specifying the percentage of file encryption, supports targeting specific directories or individual files, and appends the .frag extension to encrypted files. Sophos reported that its CryptoGuard feature blocked Frag in the observed incident and that detection for the Frag binary was subsequently added. Reporting also characterizes Frag as a cheaply produced "junk gun" ransomware, possibly self-developed by criminals or acquired from an underground marketplace for roughly $375. High-confidence indicators and artifacts mentioned in the content include exploitation of CVE-2024-40711, creation of local accounts "point" and "point2," and encrypted files bearing the .frag extension. Targeting in the cited reporting centers on organizations running Veeam backup infrastructure, which ransomware actors commonly attack to enable lateral movement, data theft, and disruption of recovery by deleting or compromising backups.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

1 CVES
CVE-2024-40711Unauthenticated RCE in Veeam Backup & ReplicationExploited in the wild

The vulnerability, CVE-2024-40711, was used as part of a threat activity cluster we named STAC 5881. Attacks leveraged compromised VPN appliances for access and used the VEEAM vulnerability to create a new local administrator account named “point”. Some cases in this cluster led to the deployment of Akira or Fog ransomware. | In a recent case MDR analysts once again observed the tactics associated with STAC 5881 – but this time observed the deployment of a previously-undocumented ransomware called “Frag”.

via sophos threat researchsophos.com
MITRE ATT&CK

Techniques & procedures

5 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

2 techniques
T1133External Remote ServicesEvidence2

Attacks leveraged compromised VPN appliances for access... Similar to the previous events, the threat actor used a compromised VPN appliance for access...

T1190Exploit Public-Facing ApplicationEvidence2

The vulnerability, CVE-2024-40711, was used as part of a threat activity cluster we named STAC 5881.

Execution

1 technique
T1059Command and Scripting InterpreterEvidence2

Frag is executed on the command line with a number of parameters...

Persistence

2 techniques
T1133External Remote ServicesEvidence2

Attacks leveraged compromised VPN appliances for access... Similar to the previous events, the threat actor used a compromised VPN appliance for access...

T1136Create AccountEvidence2

...used the VEEAM vulnerability to create a new local administrator account named “point”. Similar to the previous events... created a new account named ‘point’. However in this incident a ‘point2’ account was also created.

Impact

1 technique
T1486Data Encrypted for ImpactEvidence2

Frag is executed on the command line with a number of parameters, with one required: percentage of file encryption. The attacker can specify directories or individual files to encrypt.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities1

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping5

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.