Customer Advisory Kaseya VSA Ransomware Incident
ID: fccb50b5-11ef-59f1-981f-90b649af9de5
STIX ID: report--fccb50b5-11ef-59f1-981f-90b649af9de5
Feed Name: Mitiga
#### Executive Summary: This report documents a large-scale supply-chain ransomware attack (REvil/Sodinokibi) against Kaseya VSA on July 2, 2021, where attackers exploited a code-injection vulnerability to distribute a malicious update (agent.crt → agent.exe) via MSP-hosted VSA servers, encrypting endpoints across numerous organizations worldwide; the report includes impacted groups, a timeline, IOCs (files, hashes, registry keys, attacker IPs, log artefacts), and concrete mitigation and incident-response recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
