logo

Kaseya Ransomware Supply-Chain Attack: What We Know So Far

ID: 30c48527-1857-55ff-ab5d-97f131d3eebc

STIX ID: report--30c48527-1857-55ff-ab5d-97f131d3eebc

Feed Name: ReliaQuest Blog

Threat Score
90/100

Date Published: 2021-07-05

Date Updated: 2026-04-29

...
...

On 02 July 2021 a sophisticated supply-chain ransomware attack exploited an apparent zero-day in Kaseya VSA to distribute REvil (Sodinokibi) ransomware via malicious product updates, impacting managed service providers and their customers; the report outlines the attack stages, ransom demands (including a universal decryptor offer and Monero payment requests), attribution to REvil RaaS affiliates, and provides detection queries and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.