×

Empower Your Business with Innovation

  • Shop By Category
  • Kaseya Ransomware Supply Chain Attack: What You Need To Know

    Posted by HSSL Technologies on Aug 17th 2021

    Several hundred organizations have been targeted by the REvil (aka Sodinokibi) ransomware in a supply chain attack involving Kaseya VSA software and multiple Managed Service Providers (MSPs) who use it. News of the attack broke yesterday (Friday 3 July), prompting Kaseya to urge VSA users to shut down their VSA servers to prevent them from being compromised. The attack may have been timed to coincide with the 4th of July holiday weekend in the U.S., where many organizations may be lightly staffed.

    Are Symantec customers protected?

    Yes, Symantec Endpoint products proactively blocked tools used to deliver the ransomware payload in this wave of attacks.

    How many organizations are affected?

    According to Kaseya only a very small percentage of their customers were affected, “currently estimated at fewer than 40 worldwide”. However, each of those organizations may be MSPs with multiple customers. Current reports suggest hundreds of victims.

    How was REvil delivered to computers during these attacks?

    While the exploit used to breach Kaseya VSA server side has not yet been fully documented, it is known that the attackers delivered a malicious script and an ASCII PEM named agent.crt to Kaseya VSA clients. The dropper masqueraded inside the ASCII PEM file, which was decoded using certutil after attempts to disable Microsoft Defender. It dropped two resources, an old, but legitimate copy of Windows Defender (MsMpEng.exe) and custom malicious loader. The dropper writes the two files to disk and executes MsMpEng.exe which then side loads and executes the custom loader's export (mpsvc.dll).

    What was the motivation for the attacks?

    REvil attacks are usually financially motivated. However, there are some signs that the attacks may be politically motivated disruption. The attackers have, on occasion, appeared to have a political motive in their selection of targets.

    In this attack, strings in the payload made references to President Joe Biden, ex-president Donald Trump, and Black Lives Matter. The attackers demanded a ransom of $45,000, which may be another reference to Trump, who was the 45th president of the U.S.

    Furthermore, REvil’s Tor payment site is down at the time of writing, meaning victims will have no way of paying a ransom. Whether the group is having technical difficulties or whether it never intended to collect a ransom remains unclear.

    What is REvil/Sodinokibi?

    REvil (detected as Ransom.Sodinokibi) is a family of ransomware developed by a cybercrime group Symantec calls Leafroller. The ransomware is used in targeted attacks, where the attackers attempt to encrypt all computers on the victim’s network in the hope of extorting a large ransom. The group is known to steal victim data prior to encryption and threaten to release it unless a ransom is paid.

    Leafroller is one of the most established and prolific targeted ransomware groups in operation. Prior to its development of REvil, the group was associated with an older ransomware family known as Gandcrab. Leafroller is known to operate a Ransomware-as-a- Service, where its sells its tools to collaborators known as affiliates in exchange for a cut of any ransom payments they obtain.

    Protection/Mitigation

    Tools associated with these attacks will be detected and blocked on machines running Symantec Endpoint products.

    File-based protection:

    • Downloader
    • Heur.AdvML.C
    • Packed.Generic.618
    • Ransom.Sodinokibi
    • Trojan.Gen.2
    • Trojan.Gen.MBT
    • WS.Malware.1
    • WS.Malware.2

    Network-based protection:

    • Ransom.Gen Activity 29
    • Audit: Ransom.Gen Activity 55
    Top

    Don't Miss Out

    Sign up now to receive exclusive perks and unique promotions directly to your inbox.

    Culver Drive, 340 Irvine, CA 92604

    Tel 888.988.5472

    Copyright © HSSL Technologies. All Rights Reserved. HSSL Technologies are registered trademarks of HSSL Technologies. All other trademarks and registered trademarks brands are the sole property of their respective owners.

    HSSL Technologies (US) © 2026. All Rights Reserved.
    american expressdiners clubdiscovermaestromasterpaypalvisa