TTPs Used by REvil (Sodinokibi) Ransomware Gang in Kaseya MSP Supply-Chain Attack

Monday, 19 June 2023

Estimated reading time:2 minutes

The REvil ransomware gang targets MSPs and their customers through the Kaseya VSA cloud-based MSP platform, which allows service providers to perform patch management and customer monitoring.
1.jpeg

 

Kaseya MSP Supply-Chain Attack

Picus Labs has updated the Picus Threat Library with REvil (Sodinokibi) ransomware samples that are used in a massive cyberattack that targets multiple Managed Service Providers (MSPs) and thousands of their customers. As with all recent large-scale cyberattacks, this attack is also a supply chain attack. REvil ransomware gang targeted MSPs and their customers through Kaseya VSA cloud-based MSP platform enabling service providers to perform patch management and client monitoring.

 

Attack Simulation

You can test your security controls against this vulnerability using the Picus Security Control Validation Platform. Picus Threat Library includes the following threats for Revil (Sodinokibi) ransomware samples used in the Kaseya MSP supply-chain attack. In addition to these new samples, Picus Threat Library includes 19 Revil (Sodinokibi) ransomware variants used in previous attack campaigns. As of July 4, 2021, Picus includes 1176 ransomware threat samples for 179 malware families, including DarkRadiation, Darkside, Clop, Crysis, RagnarLocker, WastedLocker, NetWalker, and RYUK.

2.png

 

Kaseya’s Recommendations

Kaseya issued a new update, advising on-premise Kaseya partners to keep their VSA servers offline until further instructions on when it is safe to resume operations. Kaseya also stated that SaaS and Hosted VSA Servers will be operational once they have determined that they can safely restore operations.

 

Read more about Attack Life-Cycle and Tactics, Techniques and Procedures (TTPs)/ Employed MITRE ATT&CK Tactics and Techniques/ Indicators of Compromise (IOCs) here.

3.png

—–

PAMA – Official distributor of Picus in Vietnam

Translator: Nguyễn Thùy Trang
Source: www.picussecurity.com
Share this blog :

Related Blogs & News

XDR

4 min read

20June
An Introduction to Extended Detection and Response (XDR)

XDR is a platform that enables the discovery of security incidents and response by collecting and connecting information from different security produ...

androi

2 min read

22June
24000 Android apps from Play Store threaten user data

Firebase is an app hosting platform acquired by Google in 2014. According to cybersecurity experts, the developers of the 24,000 apps available on the...

SecOps

4 min read

20June
NetOps and SecOps Cooperation

Flowmon is a tool that enables the perfect synergy between NetOps and SecOps, helping businesses and organizations achieve the desired benefits.