logo

Deep Dive: Kaseya VSA Mining Payload

ID: d33d3bd1-d565-5dbd-b001-2dc67b5568e1

STIX ID: report--d33d3bd1-d565-5dbd-b001-2dc67b5568e1

Feed Name: Huntress Blog

Threat Score
70/100

Date Published: 2018-01-30

Date Updated: 2026-04-28

...
...

This Huntress report analyzes a Windows malware campaign that establishes persistence by creating scheduled tasks (including backdooring legitimate tasks) which execute Base64-encoded PowerShell payloads retrieved from Dropbox and stored in HKLM registry values; it describes architecture checks for x86/x64 payloads, obfuscation and evasion (registry path/name changes), provides IoCs and remediation/takedown actions, and notes coordination with Dropbox and updates to Kaseya removal procedures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.