logo

The Hunt to Find Origins of Kaseya's VSA Mass Ransomware Incident | Huntress

ID: e32f19a9-ac02-5cc6-8212-98dd8fcd84e1

STIX ID: report--e32f19a9-ac02-5cc6-8212-98dd8fcd84e1

Feed Name: Huntress Blog

Threat Score
75/100

Date Published: 2024-06-24

Date Updated: 2026-04-28

...
...

Huntress provides a post-incident analysis of the July 2021 REvil ransomware campaign that abused Kaseya VSA, detailing an attack chain (authentication bypass via /dl.asp using Agent GUIDs, arbitrary file upload, and remote code execution), and evaluating five plausible vectors for how valid Agent GUIDs were obtained (predictable GUIDs/display names, rogue agent registration, compromised agent hosts, other vulnerabilities including CVE-2021-30116/30117, or previously leaked GUIDs). The report highlights why only ~50–60 MSPs were impacted despite a large potential attack surface, outlines remaining intelligence gaps, and urges sharing of artifacts (e.g., Screenshot.jpg) to improve understanding and prevention.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.