Qualys VMDR Helps Organizations Detect Kaseya REvil Ransomware Exposure

The REvil ransomware group exploits a zero-day vulnerability in Kaseya VSA to compromise over a million systems worldwide. Qualys VMDR provides automated asset discovery and dynamic tagging to help security teams quickly identify and prioritize affected endpoints.

A massive REvil ransomware attack leverages a zero-day vulnerability in Kaseya's VSA product to compromise the IT infrastructure of countless organizations. By exploiting CVE-2021-30116, the ransomware-as-a-service operators deploy malicious payloads that disrupt businesses globally, affecting supermarkets, schools, and government offices. The attackers demand a staggering $70 million for a universal decryptor and threaten to leak stolen data on their dark web "Happy Blog" if the ransom remains unpaid.

Qualys VMDR offers a critical solution for organizations to automatically discover and prioritize assets affected by this widespread threat. Security teams use specific search queries within the platform to instantly identify all hosts running the Kaseya Agent software across their networks. This rapid identification capability allows defenders to quickly understand their potential exposure to the REvil ransomware campaign.

Once the vulnerable systems are identified, Qualys VMDR enables administrators to apply dynamic tags to group these at-risk assets together automatically. This continuous tagging ensures that both existing and newly deployed Kaseya systems are immediately categorized for targeted security measures. By streamlining asset visibility and prioritization, Qualys VMDR empowers organizations to respond effectively to the Kaseya VSA vulnerability and mitigate the risk of ransomware infection.

Read More at the original source →