logo

Kaseya VSA Supply Chain Ransomware Incident

ID: 7a1d5787-5a4d-5891-9dd0-ef2fcb5f1393

STIX ID: report--7a1d5787-5a4d-5891-9dd0-ef2fcb5f1393

Feed Name: CloudSEK Blog

Threat Score
90/100

Date Published: 2021-07-14

Date Updated: 2026-04-27

...
...

On 02 July 2021 Kaseya disclosed a large-scale supply-chain ransomware attack by the REvil group that exploited a zero-day authentication bypass in Kaseya VSA to upload a Base64-encoded "agent.crt" update; the payload is decoded to a dropper (agent.exe) which disables Defender, copies/renames certutil to cert.exe, decodes the payload, and DLL-sideloads a malicious mpsvc.dll via MsMpEng.exe to deploy a ransomware locker. The report provides execution details, MITRE ATT&CK mappings, file paths and hashes, domains and YARA rules, and detection notes (including renaming/copying of certutil.exe and behavioral detection recommendations).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.