REvil Ransomware Exploits Kaseya Software in Massive Supply Chain Attack

The REvil ransomware gang leverages a vulnerability in Kaseya VSA software to encrypt thousands of systems across hundreds of downstream businesses. This massive supply chain attack forces multiple organizations worldwide to shut down operations entirely.

A massive ransomware attack unfolds as the REvil gang targets Kaseya VSA, a popular remote network management software used by managed service providers (MSPs). On July 3, the attackers push a malicious hotfix that propagates through Kaseya servers, encrypting systems and shared folders at hundreds of downstream businesses. Network management software serves as an ideal hiding spot for this backdoor because these systems possess broad access and perform numerous tasks, making malicious activity incredibly difficult to monitor.

Unlike the SolarWinds incident, there is no indication that Kaseya's internal infrastructure suffers a compromise. Instead, the attackers exploit vulnerable, internet-facing VSA servers using a SQL injection vulnerability identified as CVE-2021-30116. By compromising these upstream MSP servers, the threat actors push the Sodinokibi ransomware payload downstream, making it nearly impossible for victim organizations to detect or prevent the infection before their files are encrypted.

The fallout from this attack is severe, forcing multiple organizations throughout Europe and the Asia-Pacific region to shut down their businesses entirely while they attempt to remediate the damage. REvil claims to have infected over a million systems and currently maintains an active payment portal to negotiate with victims. However, independent reporting suggests roughly 60 of Kaseya's direct customers are impacted, resulting in an estimated 800 to 1,500 compromised businesses downstream.

Read More at the original source →