logo

MSPs Beware: Attackers Targeting MSP Infrastructure to Install Ransomware

ID: 658d8ada-f9b7-59aa-ae12-24e2c7729a19

STIX ID: report--658d8ada-f9b7-59aa-ae12-24e2c7729a19

Feed Name: WatchGuard Secplicity Blog

Threat Score
88/100

Date Published: 2019-07-08

Date Updated: 2026-05-01

Author: The Editor

...
...

This report describes an active supply-chain style campaign where sophisticated threat actors compromise MSPs—through RDP, credential theft, or known software flaws—and abuse legitimate RMM/management consoles (including Webroot, ConnectWise/Kaseya) to deploy Sodinokibi ransomware broadly to MSPs and their customers; it details technical TTPs (PowerShell/PowerSploit reflective PE injection, disabling security controls), a timeline of related incidents, observed impacts, and recommended mitigations (MFA, patching, VPN, advanced anti-malware, backups).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.