Huntress VSA Vaccine: Acting Like Hackers To Protect Our Partners | Huntress
ID: fab984ab-3405-5e58-8b1c-4a22a1580376
STIX ID: report--fab984ab-3405-5e58-8b1c-4a22a1580376
Feed Name: Huntress Blog
Threat Score
On July 2, 2021 REvil used compromised Kaseya VSA servers to push Sodinokibi ransomware to MSP clients; Huntress analyzed the payload (noting the use of a renamed certutil to decode a base64 agent.crt into agent.exe) and issued an emergency mitigation by deploying a benign agent.exe 'vaccine' to endpoints while sharing hashes and guidance with vendors and partners.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
