Deep Dive: Kaseya VSA Mining Payload
ID: d33d3bd1-d565-5dbd-b001-2dc67b5568e1
STIX ID: report--d33d3bd1-d565-5dbd-b001-2dc67b5568e1
Feed Name: Huntress Blog
This Huntress report analyzes a Windows malware campaign that establishes persistence by creating scheduled tasks (including backdooring legitimate tasks) which execute Base64-encoded PowerShell payloads retrieved from Dropbox and stored in HKLM registry values; it describes architecture checks for x86/x64 payloads, obfuscation and evasion (registry path/name changes), provides IoCs and remediation/takedown actions, and notes coordination with Dropbox and updates to Kaseya removal procedures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
