Rapid Response: Mass MSP Ransomware Incident | Huntress
ID: 8825c535-9416-58b7-b224-bbaf04e53478
STIX ID: report--8825c535-9416-58b7-b224-bbaf04e53478
Feed Name: Huntress Blog
Huntress details analysis of the Kaseya VSA supply-chain ransomware attack (July 2021) where attackers used an authentication bypass, arbitrary file upload and SQL/command injection to upload agent.crt/Screenshot.jpg, decode agent.exe (REvil/Sodinokibi), sideload a malicious mpsvc.dll via MsMpEng.exe and deploy ransomware across MSPs and their customers; the report includes IOCs (IPs, filenames, hashes, registry keys), observed procedures, timeline updates, and notes that Kaseya released a patch (9.5.7a) which Huntress validated.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
