The Hunt to Find Origins of Kaseya's VSA Mass Ransomware Incident | Huntress
ID: e32f19a9-ac02-5cc6-8212-98dd8fcd84e1
STIX ID: report--e32f19a9-ac02-5cc6-8212-98dd8fcd84e1
Feed Name: Huntress Blog
Huntress provides a post-incident analysis of the July 2021 REvil ransomware campaign that abused Kaseya VSA, detailing an attack chain (authentication bypass via /dl.asp using Agent GUIDs, arbitrary file upload, and remote code execution), and evaluating five plausible vectors for how valid Agent GUIDs were obtained (predictable GUIDs/display names, rogue agent registration, compromised agent hosts, other vulnerabilities including CVE-2021-30116/30117, or previously leaked GUIDs). The report highlights why only ~50–60 MSPs were impacted despite a large potential attack surface, outlines remaining intelligence gaps, and urges sharing of artifacts (e.g., Screenshot.jpg) to improve understanding and prevention.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
