ADVERTISEMENT

An in-depth analysis of the Kaseya ransomware attack: here’s what you need to know

Kaseya on phone and PC screen
Pierluigi Paganini
Pierluigi Paganini Contributor
July 19, 2021 Updated: December 7, 2023 5 min read
The threat actors attempted to maximize the impact of their attack by launching it on Friday, ahead of the July 4 holiday in the US.

A deeper analysis of the attack

We are monitoring a REvil 'supply chain' attack outbreak, which seems to stem from a malicious Kaseya update. REvil binary C:\Windows\mpsvc.dll is side-loaded into a legit Microsoft Defender copy, copied into C:\Windows\MsMpEng.exe to run the encryption from a legit process.
Ransomware message from REvil
Digital signature on mpsvc.dll
Digital signature on mpsvc.dll (Source: Trustwave)

The zero-day vulnerability exploited by REvil gang

ADVERTISEMENT

The impact

The remediation

  • CVE-2021-30116 – A credentials leak and business logic flaw, to be included in 9.5.7
  • CVE-2021-30117 – An SQL injection vulnerability, fixed in VSA 9.5.6.
  • CVE-2021-30118 – A Remote Code Execution vulnerability, fixed in VSA 9.5.6.
  • CVE-2021-30119 – A Cross Site Scripting vulnerability, to be included in 9.5.7
  • CVE-2021-30120 – 2FA bypass, to be resolved in v9.5.7
  • CVE-2021-30121 – A Local File Inclusion vulnerability, fixed in VSA 9.5.6.
  • CVE-2021-30201 – A XML External Entity vulnerability, fixed in VSA 9.5.6.
ADVERTISEMENT