Kaseya Ransomware Supply-Chain Attack: What We Know So Far
ID: 30c48527-1857-55ff-ab5d-97f131d3eebc
STIX ID: report--30c48527-1857-55ff-ab5d-97f131d3eebc
Feed Name: ReliaQuest Blog
Threat Score
On 02 July 2021 a sophisticated supply-chain ransomware attack exploited an apparent zero-day in Kaseya VSA to distribute REvil (Sodinokibi) ransomware via malicious product updates, impacting managed service providers and their customers; the report outlines the attack stages, ransom demands (including a universal decryptor offer and Monero payment requests), attribution to REvil RaaS affiliates, and provides detection queries and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
