KASEYA Supply Chain Ransomware Attack
ID: 4811da03-dfa8-5027-a596-c0ec04cbb6f6
STIX ID: report--4811da03-dfa8-5027-a596-c0ec04cbb6f6
Feed Name: Zscaler Security Research Blog
On July 2, 2021, threat actors exploited a zero-day in on-premises Kaseya VSA to distribute a malicious script that deployed REvil/Sodinokibi ransomware to downstream managed clients; the report details the infection chain (certutil decoding, agent.exe dropper, DLL side-loading via MsMpEng.exe), payload behavior (disabling Defender features, custom packing, RC4-config, Curve25519/Salsa20 file encryption, registry keys under SOFTWARE\BlackLivesMatter), post-encryption actions (ransom notes, wallpaper, ransom demand), and provides IOCs including file hashes and beacon domain lists for detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
