logo

Huntress VSA Vaccine: Acting Like Hackers To Protect Our Partners | Huntress

ID: fab984ab-3405-5e58-8b1c-4a22a1580376

STIX ID: report--fab984ab-3405-5e58-8b1c-4a22a1580376

Feed Name: Huntress Blog

Threat Score
88/100

Date Published: 2024-06-24

Date Updated: 2026-04-28

...
...

On July 2, 2021 REvil used compromised Kaseya VSA servers to push Sodinokibi ransomware to MSP clients; Huntress analyzed the payload (noting the use of a renamed certutil to decode a base64 agent.crt into agent.exe) and issued an emergency mitigation by deploying a benign agent.exe 'vaccine' to endpoints while sharing hashes and guidance with vendors and partners.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.