frag-blog@proton.mefrag-blog@tutamail.com
Frag
Frag is a previously undocumented ransomware family observed by Sophos X-Ops in late 2024 and associated with threat activity cluster STAC 5881.
Profile source: Mallory opens in a new tabFrag
Family profile
Frag is a previously undocumented ransomware family observed by Sophos X-Ops in late 2024 and associated with threat activity cluster STAC 5881. In the reported incidents, the operators gained initial access via compromised VPN appliances and then exploited Veeam Backup & Replication remote code execution vulnerability CVE-2024-40711 on backup servers. The same cluster had previously deployed Akira and Fog ransomware, and Sophos and Agger Labs noted that Frag-related tradecraft overlaps with tactics seen in Akira- and Fog-associated activity, suggesting either a new ransomware actor using similar methods or operational overlap. In the Frag case, the attackers used the Veeam flaw to create local administrator accounts named "point" and "point2". Frag is a command-line ransomware that requires a parameter specifying the percentage of file encryption, supports targeting specific directories or individual files, and appends the .frag extension to encrypted files. Sophos reported that its CryptoGuard feature blocked Frag in the observed incident and that detection for the Frag binary was subsequently added. Reporting also characterizes Frag as a cheaply produced "junk gun" ransomware, possibly self-developed by criminals or acquired from an underground marketplace for roughly $375. High-confidence indicators and artifacts mentioned in the content include exploitation of CVE-2024-40711, creation of local accounts "point" and "point2," and encrypted files bearing the .frag extension. Targeting in the cited reporting centers on organizations running Veeam backup infrastructure, which ransomware actors commonly attack to enable lateral movement, data theft, and disruption of recovery by deleting or compromising backups.
Operational record
Published indicators
Exploited software
Vulnerabilities linked to Frag
1 CVEsMITRE ATT&CK