Analysis of Minebridge & Kaseya Supply Chain Attacks
ID: 44b11794-663e-55a9-9c09-8ea83476d7a2
STIX ID: report--44b11794-663e-55a9-9c09-8ea83476d7a2
Feed Name: Zscaler Security Research Blog
Zscaler ThreatLabZ analyzes two high‑impact incidents: a July 2021 REvil supply‑chain ransomware attack that exploited a zero‑day in Kaseya VSA to distribute a packed REvil PE payload to on‑premise clients and propagate to over 1,000 downstream organizations, and a MineBridge RAT campaign that employs malicious TradingView‑lookalike installers, TeamViewer DLL side‑loading, scheduled tasks, PowerShell, and SSH tunnels; the report provides technical breakdowns, observed evasion techniques, and recommends restricting external access and adopting Zero Trust protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
