Kaseya supply chain attack: What you need to know
ID: 93929ebd-ffeb-56d7-8e16-28818b219b4e
STIX ID: report--93929ebd-ffeb-56d7-8e16-28818b219b4e
Feed Name: Expel Blog
Date Published: 2021-07-06
Date Updated: 2026-04-27
Author: Ben Brigida; Matthew Berninger; Jon Hencinski; Evan Reichard; Ray Pugh
Kaseya experienced a large-scale supply-chain ransomware attack on July 2, 2021 in which the REvil group exploited a zero-day (CVE-2021-30116) in Kaseya VSA to distribute a malicious update that dropped a REvil encryptor and side-loaded a malicious mpsvc.dll into a legitimate Microsoft Defender binary, impacting MSPs and hundreds of U.S. businesses; the report includes technical details, IOCs (file paths, hashes, and an onion C2), and immediate mitigation and detection steps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
