Newsletter Archives
-
Kaseya VSA has been hit with a ransomware attack
https://www.reddit.com/r/msp/comments/ocggbv/crticial_ransomware_incident_in_progress/
“We are monitoring a REvil ‘supply chain’ attack outbreak, which seems to stem from a malicious Kaseya update. REvil binary C:\Windows\mpsvc.dll is side-loaded into a legit Microsoft Defender copy, copied into C:\Windows\MsMpEng.exe to run the encryption from a legit process.”
This not good for those who rely on consultants who then use common tools. Kaseya is the name of a company that provides various tools for consultants to remotely access and manage networks for their customers.
Consumer/Home user impact: You don’t use Kasaya VSA so you are safe.
Small business impact/Consultant impact: So far it looks like it’s only 4 MSPs that Huntresslabs are tracking, but you may want to check your networks to be safe.