Kaseya VSA Supply-Chain Ransomware Incident — REvil/Sodinokibi Exploits CVE-2021-30116/30117/30118/30119/30120/30121 to Compromise 60 MSPs and 1,500+ Downstream Organizations

Kaseya VSA Supply-Chain Ransomware Incident (TL-2026-1649), also tracked as Kaseya VSA Supply-Chain Attack, is a critical-severity ransomware operation scored CVSS 9.8, first published 2026-07-23. It is attributed to REvil (Russia) with high confidence, affects Kaseya Virtual System Administrator (VSA) — on-premises, references 7 CVEs (CVE-2021-30116, CVE-2021-30117, CVE-2021-30118), maps to 27 MITRE ATT&CK techniques (T1018, T1021, T1036.003), and is covered by 9 detection rules and 21 indicators of compromise.

Key facts for TL-2026-1649

Threat ID
TL-2026-1649
Also known as
Kaseya VSA Supply-Chain Attack, Operation Kaseya, REvil Kaseya Attack
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
RESOLVED
Category
RANSOMWARE
First published
2026-07-23
Last reviewed
2026-07-23
Attribution
REvil
Attribution confidence
HIGH
Nation-state nexus
Russia
Motivation
FINANCIAL
Target sectors
msp, retail, education, government administration, finance, health, technology, manufacturing
Target regions
North America, Europe, Oceania, Africa, Worldwide
Detection rules
9
Indicators of compromise
21

Malware and tooling in Kaseya VSA Supply-Chain Ransomware Incident

Malware and tooling: REvil / Sodinokibi

The REvil/Sodinokibi ransomware-as-a-service operation chained multiple zero-day vulnerabilities (authentication bypass, SQL injection, arbitrary file upload, remote code execution) in Kaseya Virtual System Administrator (VSA) on-premises servers to push a trojanized 'Kaseya VSA Agent Hot-fix' to managed endpoints, disabling Windows Defender and side-loading the Sodinokibi encryptor via a signed, patched copy of MsMpEng.exe. Roughly 60 MSPs and 800–1,500 downstream businesses (including Coop Sweden, 800 stores) were encrypted; REvil demanded $70M for a universal decryptor before the FBI obtained the key and REvil's infrastructure vanished on July 13, 2021.

How Kaseya VSA Supply-Chain Ransomware Incident works

On July 2, 2021, the REvil (Sodinokibi) ransomware-as-a-service affiliate operation launched one of the largest supply-chain ransomware attacks on record, exploiting Kaseya VSA — a widely deployed remote monitoring and management (RMM) platform used by managed service providers (MSPs) — to distribute ransomware to thousands of downstream customer endpoints in a single coordinated wave.

The intrusion began with exploitation of an authentication bypass vulnerability in the Kaseya VSA web interface (tracked publicly as part of the CVE-2021-30116/30117/30118/30119/30120/30121/30201 cluster first responsibly disclosed by the Dutch Institute for Vulnerability Disclosure, DIVD, on April 6, 2021). Attackers used the authentication bypass to obtain an authenticated session on internet-facing on-premises VSA servers, then chained an SQL injection flaw and an arbitrary file upload / code injection primitive to gain administrative control of the VSA management console without valid credentials.

From the compromised VSA server, the attackers abused the platform's own legitimate agent-update distribution mechanism to push a fraudulent update, disguised as a 'Kaseya VSA Agent Hot-fix,' to every endpoint the server managed — a textbook software-supply-chain trust abuse. The malicious update was delivered as an encoded file named agent.crt, decoded on-endpoint to agent.exe. Execution first invoked a PowerShell one-liner that disabled Windows Defender real-time monitoring, disabled Windows Error Recovery, and cleared event logs, then renamed certutil.exe to cert.exe to base64-decode the embedded payload while evading naive detection rules keyed on certutil.exe invocation.

agent.exe was signed with a certificate issued to 'PB03 TRANSPORT LTD' (subsequently revoked) and dropped two components into C:\Windows\: a deliberately outdated, legitimately signed copy of the Microsoft Defender executable (renamed MsMpEng.exe) and a malicious mpsvc.dll. Because the vulnerable, legitimate MsMpEng.exe loads mpsvc.dll from its own directory without integrity verification, launching MsMpEng.exe caused Windows itself to load and execute the REvil encryptor via DLL side-loading — a living-off-the-land technique that let the ransomware execute under the guise of a trusted, digitally-signed Microsoft binary and evade many AV/EDR heuristics tuned to distrust unsigned executables.

Once loaded, the Sodinokibi/REvil encryptor created the registry key HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\BlackLivesMatter to store runtime configuration, including a per-victim public/private keypair generated via an embedded elliptic-curve scheme and the file extension to append to encrypted files. Files were encrypted using a Salsa20/AES hybrid scheme; the private key material needed for decryption was itself encrypted under a master public key controlled by the REvil operators and never transmitted off-host in plaintext, making the encryption cryptographically irreversible without cooperation from the attackers (or, ultimately, the FBI-obtained master key). Volume Shadow Copies were deleted and safe-mode boot recovery paths disabled to frustrate remediation.

The blast radius was compounded by Kaseya VSA's typical MSP deployment model: a single compromised on-premises VSA server often manages hundreds of downstream client endpoints across dozens of separate customer organizations, so encrypting one VSA console cascaded ransomware to every managed endpoint simultaneously. Kaseya identified roughly 50–60 MSPs running vulnerable on-premises VSA servers as the initial infection vector and proactively shut down its VSA SaaS infrastructure as a precaution, even though the SaaS environment itself was not confirmed compromised. Kaseya estimated 800–1,500 downstream businesses were ultimately encrypted; the highest-profile victim was Swedish supermarket chain Coop, which was forced to close roughly 800 stores for several days because point-of-sale systems were unusable, and several New Zealand schools also lost access to critical systems.

On July 5, 2021, a REvil-affiliated 'Happy Blog' post demanded $70 million in Bitcoin for a single universal decryptor capable of unlocking every victim encrypted in the campaign, while offering smaller individualized ransoms to specific organizations. Kaseya publicly stated it would not pay the ransom and worked with FireEye/Mandiant, the FBI, CISA, and Dutch researchers on incident response and a patch. On July 13, 2021, REvil's public-facing infrastructure — including its Tor payment portal and Happy Blog leak site — abruptly went offline; researchers assessed this reflected either a law-enforcement takedown, a voluntary shutdown by the operators fearing retaliation following high-level U.S.-Russia diplomatic pressure, or both. On July 21–23, 2021, Kaseya received a universal decryptor key from what it described as a 'trusted third party' — later confirmed via congressional testimony to be the FBI, which had obtained the REvil master decryption key through undisclosed means but withheld it from victims for roughly three weeks while weighing a disruption operation against REvil's infrastructure, a decision that drew significant criticism.

Attribution and downstream law enforcement action: Ukrainian national Yaroslav Vasinskyi was identified as a REvil affiliate responsible for deploying the ransomware in the Kaseya attack and was arrested in Poland on October 8, 2021, extradited to the United States, convicted, and sentenced on May 1, 2024 to 13 years 7 months in federal prison plus over $16 million in restitution. A second individual, Russian national Yevgeniy Polyanin, was separately charged for REvil-affiliate ransomware activity including Kaseya-related attacks; the U.S. Treasury and State Department additionally sanctioned REvil-linked infrastructure and offered a $10 million reward for information on REvil leadership. In November 2021, Russian authorities announced arrests of several individuals linked to REvil at the request of U.S. authorities, though the group's core leadership largely evaded lasting prosecution and REvil-derived tooling/personnel are assessed to have resurfaced in successor ransomware-as-a-service brands.

The incident remains a canonical case study in software-supply-chain risk for the MSP/RMM ecosystem: it demonstrated how a single vulnerable management platform can be weaponized to achieve mass simultaneous ransomware deployment across otherwise unrelated victim organizations that have no direct relationship with the attacker or even direct awareness that they run the vulnerable software, since the vulnerable server was operated by their MSP rather than by the victims themselves.

MITRE ATT&CK techniques used in TL-2026-1649

Discovery

T1018 Remote System Discovery; T1082 System Information Discovery

Lateral Movement

T1021 Remote Services

Defense Evasion

T1036.003 Rename Legitimate Utilities; T1036.005 Match Legitimate Resource Name or Location; T1070.004 File Deletion; T1140 Deobfuscate/Decode Files or Information

Execution

T1059.001 PowerShell; T1106 Native API

Command and Control

T1071.001 Web Protocols; T1090 Proxy

defense-impairment

T1112 Modify Registry; T1553.002 Code Signing; T1685 Disable or Modify Tools; T1685.005 Clear Windows Event Logs

Initial Access

T1190 Exploit Public-Facing Application; T1195 Supply Chain Compromise; T1199 Trusted Relationship

Impact

T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery; T1491 Defacement

Persistence

T1505 Server Software Component

Credential Access

T1552 Unsecured Credentials

stealth

T1574.001 DLL

Resource Development

T1584.006 Web Services; T1588.003 Code Signing Certificates

Affected products and versions in Kaseya VSA Supply-Chain Ransomware Incident

  • Kaseya — Virtual System Administrator (VSA) — on-premises
    Vulnerable versions: 9.5.4 and earlier; 9.5.5; 9.5.6
    Fixed in: 9.5.7a and later
  • Kaseya — Virtual System Administrator (VSA) — SaaS
    Vulnerable versions: Proactively taken offline out of caution; not confirmed compromised
    Fixed in: Restored after security hardening review

Remediation for Kaseya VSA Supply-Chain Ransomware Incident

Patches

  • Kaseya VSA 9.5.5 — patches CVE-2021-30118 (Remote Code Execution)
  • Kaseya VSA 9.5.6 — patches CVE-2021-30117 (SQL Injection), CVE-2021-30121 (Local File Inclusion), CVE-2021-30201 (XML External Entity)
  • Kaseya VSA 9.5.7a — patches CVE-2021-30116 (Credentials Leak / Business Logic), CVE-2021-30119 (Cross-Site Scripting), CVE-2021-30120 (Two-Factor Authentication Bypass)

Immediate actions

  • Shut down on-premises Kaseya VSA servers immediately and disconnect from the network until the vendor-confirmed patched build (VSA 9.5.7a or later) is applied
  • Block all known campaign IOC IP addresses (18.223.199.234, 161.35.239.148, 35.226.94.113, 162.253.124.162) at perimeter firewalls and proxies
  • Enable Windows Defender / EDR tamper protection to prevent malicious PowerShell from disabling real-time protection
  • Search all endpoints for the files agent.crt, agent.exe, and mpsvc.dll and the registry key HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\BlackLivesMatter; isolate any host where they are found
  • Run the Kaseya-published VSA Detection Tool / Compromise Detection Tool across all managed endpoints
  • Preserve KaseyaEdgeServices logs in %ProgramData%\Kaseya\Log\ and full memory/disk images before remediation for forensics

Workarounds

  • Take VSA on-premises servers fully offline until the certified-clean 9.5.7a (or later) build can be deployed
  • Restrict VSA server inbound access to an allowlist of known-good management IP addresses only
  • Disable automatic agent hot-fix/update push mechanisms until server integrity is confirmed

Longer-term hardening

  • Deploy EDR with behavioral detection tuned to flag DLL side-loading via renamed/relocated Microsoft signed binaries (e.g., MsMpEng.exe launched from non-standard paths)
  • Restrict and monitor RMM/VSA administrative interfaces behind VPN or dedicated admin network segmentation, never expose management consoles directly to the internet
  • Implement application allowlisting to prevent execution of unsigned or unexpectedly-signed binaries from user-writable and temp directories
  • Enforce MFA on all RMM platform accounts and require MFA for all customer-facing services delivered through MSP tooling
  • Adopt a least-privilege model for MSP-to-customer trust relationships; segment MSP tooling network access from core customer production environments

CVEs associated with Kaseya VSA Supply-Chain Ransomware Incident

CVE-2021-30116, CVE-2021-30117, CVE-2021-30118, CVE-2021-30119, CVE-2021-30120, CVE-2021-30121, CVE-2021-30201

Weaknesses (CWE) in Kaseya VSA Supply-Chain Ransomware Incident

CWE-89, CWE-94, CWE-798, CWE-79, CWE-287, CWE-434, CWE-611, CWE-22

Timeline of Kaseya VSA Supply-Chain Ransomware Incident

  • Dutch Institute for Vulnerability Disclosure (DIVD) researcher discovers six zero-day vulnerabilities in Kaseya VSA on-premises software during independent research.
  • DIVD identifies a seventh related vulnerability (XML External Entity, later CVE-2021-30201) in the same VSA codebase.
  • DIVD privately notifies Kaseya of the vulnerabilities; Kaseya begins a phased remediation and patch-development process with DIVD.
  • Kaseya VSA 9.5.5 released, patching CVE-2021-30118 (Remote Code Execution).
  • Kaseya VSA 9.5.6 released, patching CVE-2021-30117 (SQL Injection), CVE-2021-30121 (Local File Inclusion), and CVE-2021-30201 (XML External Entity); three critical flaws — including the authentication bypass — remained unpatched.
  • Kaseya proactively shuts down its VSA SaaS servers and instructs all on-premises VSA customers to immediately take their servers offline pending investigation.
  • REvil affiliates exploit the still-unpatched authentication bypass and chained flaws against internet-facing on-premises Kaseya VSA servers, push a trojanized 'Kaseya VSA Agent Hot-fix' (agent.crt) to managed endpoints, and detonate the Sodinokibi encryptor via MsMpEng.exe/mpsvc.dll DLL side-loading across roughly 60 MSPs and their downstream customers.
  • CISA and the FBI publish joint guidance for MSPs and downstream customers affected by the Kaseya VSA supply-chain ransomware attack, recommending the Kaseya Compromise Detection Tool, MFA, and RMM network segmentation.
  • REvil publishes a 'Happy Blog' post demanding $70 million in Bitcoin for a single universal decryptor covering all Kaseya-campaign victims, alongside smaller individualized ransom offers.
  • Kaseya releases VSA 9.5.7a, patching the remaining critical vulnerabilities including CVE-2021-30116 (authentication bypass / credentials leak), CVE-2021-30119 (XSS), and CVE-2021-30120 (2FA bypass).
  • REvil's public Tor payment portal and Happy Blog leak site abruptly go offline, coinciding with heightened U.S. diplomatic pressure on Russia; researchers assess a possible law-enforcement or voluntary shutdown.
  • Kaseya receives a universal REvil decryption key from a 'trusted third party' (later confirmed to be the FBI) and distributes it to victims; Kaseya confirms it did not pay any ransom.
  • Ukrainian national Yaroslav Vasinskyi, identified as the REvil affiliate who deployed the ransomware in the Kaseya attack, is arrested in Poland on a U.S. warrant.
  • U.S. Treasury sanctions REvil-linked entities and DOJ unseals charges against Vasinskyi and Russian national Yevgeniy Polyanin for REvil ransomware activity, including the Kaseya campaign; State Department offers a $10 million reward for information on REvil leadership.
  • Yaroslav Vasinskyi is sentenced to 13 years 7 months in federal prison and ordered to pay over $16 million in restitution for his role in the Kaseya VSA ransomware attack.

Sources cited for Kaseya VSA Supply-Chain Ransomware Incident

Threats related to Kaseya VSA Supply-Chain Ransomware Incident

Detection coverage for TL-2026-1649

As of 2026-07-23, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1649 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats