Massive REvil Ransomware Hits Thousands via Kaseya Supply Chain
The REvil ransomware gang exploits a Kaseya VSA vulnerability to encrypt thousands of systems across hundreds of downstream businesses. This massive supply chain attack forces organizations worldwide to shut down operations entirely.
A malicious hotfix pushes the REvil ransomware, also known as Sodinokibi, to thousands of computers through Kaseya VSA servers on July 3rd. Because Kaseya VSA is a popular remote network management tool used by managed service providers (MSPs), the attack rapidly spreads downstream to hundreds of different businesses. Network management software serves as a perfect hiding spot for this backdoor since these systems possess broad access and perform numerous tasks that evade easy monitoring.
Unlike the SolarWinds attack, there is no indication that Kaseya's internal infrastructure suffers a compromise. Instead, the attackers exploit vulnerable, internet-facing VSA servers using a SQL injection vulnerability identified as CVE-2021-30116. This method allows the threat actors to use the MSP servers as backdoors, making it nearly impossible for downstream victims to detect or prevent the infection as the ransomware flows through the supply chain.
The blast radius of this administrative compromise is enormous, forcing multiple organizations throughout Europe and APAC to shut down their businesses entirely while they attempt to remediate. REvil claims responsibility for the attack, actively operates a live payment portal, and boasts of infecting over a million systems. However, current reporting indicates that roughly 60 of Kaseya’s direct customers experience impact, resulting in an estimated 800 to 1,500 compromised businesses downstream.