logo

KASEYA Supply Chain Ransomware Attack

ID: 4811da03-dfa8-5027-a596-c0ec04cbb6f6

STIX ID: report--4811da03-dfa8-5027-a596-c0ec04cbb6f6

Feed Name: Zscaler Security Research Blog

Threat Score
90/100

Date Published: 2025-09-18

Date Updated: 2026-05-01

...
...

On July 2, 2021, threat actors exploited a zero-day in on-premises Kaseya VSA to distribute a malicious script that deployed REvil/Sodinokibi ransomware to downstream managed clients; the report details the infection chain (certutil decoding, agent.exe dropper, DLL side-loading via MsMpEng.exe), payload behavior (disabling Defender features, custom packing, RC4-config, Curve25519/Salsa20 file encryption, registry keys under SOFTWARE\BlackLivesMatter), post-encryption actions (ransom notes, wallpaper, ransom demand), and provides IOCs including file hashes and beacon domain lists for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.