logo

Rapid Response: Mass MSP Ransomware Incident | Huntress

ID: 8825c535-9416-58b7-b224-bbaf04e53478

STIX ID: report--8825c535-9416-58b7-b224-bbaf04e53478

Feed Name: Huntress Blog

Threat Score
90/100

Date Published: 2024-06-24

Date Updated: 2026-04-28

...
...

Huntress details analysis of the Kaseya VSA supply-chain ransomware attack (July 2021) where attackers used an authentication bypass, arbitrary file upload and SQL/command injection to upload agent.crt/Screenshot.jpg, decode agent.exe (REvil/Sodinokibi), sideload a malicious mpsvc.dll via MsMpEng.exe and deploy ransomware across MSPs and their customers; the report includes IOCs (IPs, filenames, hashes, registry keys), observed procedures, timeline updates, and notes that Kaseya released a patch (9.5.7a) which Huntress validated.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.