Kaseya VSA Supply Chain Ransomware Incident
ID: 7a1d5787-5a4d-5891-9dd0-ef2fcb5f1393
STIX ID: report--7a1d5787-5a4d-5891-9dd0-ef2fcb5f1393
Feed Name: CloudSEK Blog
On 02 July 2021 Kaseya disclosed a large-scale supply-chain ransomware attack by the REvil group that exploited a zero-day authentication bypass in Kaseya VSA to upload a Base64-encoded "agent.crt" update; the payload is decoded to a dropper (agent.exe) which disables Defender, copies/renames certutil to cert.exe, decodes the payload, and DLL-sideloads a malicious mpsvc.dll via MsMpEng.exe to deploy a ransomware locker. The report provides execution details, MITRE ATT&CK mappings, file paths and hashes, domains and YARA rules, and detection notes (including renaming/copying of certutil.exe and behavioral detection recommendations).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
