Breaking Alert: MSP Targeted Ransomware Attack (Kaseya Supply Chain Attack)
ID: afaa4810-4efb-5eaa-afac-f2f715a53ea3
STIX ID: report--afaa4810-4efb-5eaa-afac-f2f715a53ea3
Feed Name: WatchGuard Secplicity Blog
Executive summary: On July 2, a REvil ransomware supply-chain attack exploited unpatched vulnerabilities in on‑premises Kaseya VSA to infect Managed Service Providers and downstream customers (reported ~1500 impacted); the report documents the timeline, detailed TTPs (malicious CMD/Powershell chain, certutil decoding of agent.exe, DLL hijacking via MsMpEng and mpsvc.dll), detection capabilities of vendor products, IoCs, and immediate mitigations including taking VSA servers offline and applying vendor runbook/patches.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
