MSPs Beware: Attackers Targeting MSP Infrastructure to Install Ransomware
ID: 658d8ada-f9b7-59aa-ae12-24e2c7729a19
STIX ID: report--658d8ada-f9b7-59aa-ae12-24e2c7729a19
Feed Name: WatchGuard Secplicity Blog
This report describes an active supply-chain style campaign where sophisticated threat actors compromise MSPs—through RDP, credential theft, or known software flaws—and abuse legitimate RMM/management consoles (including Webroot, ConnectWise/Kaseya) to deploy Sodinokibi ransomware broadly to MSPs and their customers; it details technical TTPs (PowerShell/PowerSploit reflective PE injection, disabling security controls), a timeline of related incidents, observed impacts, and recommended mitigations (MFA, patching, VPN, advanced anti-malware, backups).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
