logo

Breaking Alert: MSP Targeted Ransomware Attack (Kaseya Supply Chain Attack)

ID: afaa4810-4efb-5eaa-afac-f2f715a53ea3

STIX ID: report--afaa4810-4efb-5eaa-afac-f2f715a53ea3

Feed Name: WatchGuard Secplicity Blog

Threat Score
90/100

Date Published: 2021-07-02

Date Updated: 2026-05-01

Author: The Editor

...
...

Executive summary: On July 2, a REvil ransomware supply-chain attack exploited unpatched vulnerabilities in on‑premises Kaseya VSA to infect Managed Service Providers and downstream customers (reported ~1500 impacted); the report documents the timeline, detailed TTPs (malicious CMD/Powershell chain, certutil decoding of agent.exe, DLL hijacking via MsMpEng and mpsvc.dll), detection capabilities of vendor products, IoCs, and immediate mitigations including taking VSA servers offline and applying vendor runbook/patches.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.