Kaseya VSA Supply-Chain Ransomware Incident — REvil/Sodinokibi Exploits CVE-2021-30116/30117/30118/30119/30120/30121 to Compromise 60 MSPs and 1,500+ Downstream Organizations
Kaseya VSA Supply-Chain Ransomware Incident (TL-2026-1649), also tracked as Kaseya VSA Supply-Chain Attack, is a critical-severity ransomware operation scored CVSS 9.8, first published 2026-07-23. It is attributed to REvil (Russia) with high confidence, affects Kaseya Virtual System Administrator (VSA) — on-premises, references 7 CVEs (CVE-2021-30116, CVE-2021-30117, CVE-2021-30118), maps to 27 MITRE ATT&CK techniques (T1018, T1021, T1036.003), and is covered by 9 detection rules and 21 indicators of compromise.
Key facts for TL-2026-1649
- Threat ID
- TL-2026-1649
- Also known as
- Kaseya VSA Supply-Chain Attack, Operation Kaseya, REvil Kaseya Attack
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- RESOLVED
- Category
- RANSOMWARE
- First published
- 2026-07-23
- Last reviewed
- 2026-07-23
- Attribution
- REvil
- Attribution confidence
- HIGH
- Nation-state nexus
- Russia
- Motivation
- FINANCIAL
- Target sectors
- msp, retail, education, government administration, finance, health, technology, manufacturing
- Target regions
- North America, Europe, Oceania, Africa, Worldwide
- Detection rules
- 9
- Indicators of compromise
- 21
Malware and tooling in Kaseya VSA Supply-Chain Ransomware Incident
Malware and tooling: REvil / Sodinokibi
The REvil/Sodinokibi ransomware-as-a-service operation chained multiple zero-day vulnerabilities (authentication bypass, SQL injection, arbitrary file upload, remote code execution) in Kaseya Virtual System Administrator (VSA) on-premises servers to push a trojanized 'Kaseya VSA Agent Hot-fix' to managed endpoints, disabling Windows Defender and side-loading the Sodinokibi encryptor via a signed, patched copy of MsMpEng.exe. Roughly 60 MSPs and 800–1,500 downstream businesses (including Coop Sweden, 800 stores) were encrypted; REvil demanded $70M for a universal decryptor before the FBI obtained the key and REvil's infrastructure vanished on July 13, 2021.
How Kaseya VSA Supply-Chain Ransomware Incident works
On July 2, 2021, the REvil (Sodinokibi) ransomware-as-a-service affiliate operation launched one of the largest supply-chain ransomware attacks on record, exploiting Kaseya VSA — a widely deployed remote monitoring and management (RMM) platform used by managed service providers (MSPs) — to distribute ransomware to thousands of downstream customer endpoints in a single coordinated wave.
The intrusion began with exploitation of an authentication bypass vulnerability in the Kaseya VSA web interface (tracked publicly as part of the CVE-2021-30116/30117/30118/30119/30120/30121/30201 cluster first responsibly disclosed by the Dutch Institute for Vulnerability Disclosure, DIVD, on April 6, 2021). Attackers used the authentication bypass to obtain an authenticated session on internet-facing on-premises VSA servers, then chained an SQL injection flaw and an arbitrary file upload / code injection primitive to gain administrative control of the VSA management console without valid credentials.
From the compromised VSA server, the attackers abused the platform's own legitimate agent-update distribution mechanism to push a fraudulent update, disguised as a 'Kaseya VSA Agent Hot-fix,' to every endpoint the server managed — a textbook software-supply-chain trust abuse. The malicious update was delivered as an encoded file named agent.crt, decoded on-endpoint to agent.exe. Execution first invoked a PowerShell one-liner that disabled Windows Defender real-time monitoring, disabled Windows Error Recovery, and cleared event logs, then renamed certutil.exe to cert.exe to base64-decode the embedded payload while evading naive detection rules keyed on certutil.exe invocation.
agent.exe was signed with a certificate issued to 'PB03 TRANSPORT LTD' (subsequently revoked) and dropped two components into C:\Windows\: a deliberately outdated, legitimately signed copy of the Microsoft Defender executable (renamed MsMpEng.exe) and a malicious mpsvc.dll. Because the vulnerable, legitimate MsMpEng.exe loads mpsvc.dll from its own directory without integrity verification, launching MsMpEng.exe caused Windows itself to load and execute the REvil encryptor via DLL side-loading — a living-off-the-land technique that let the ransomware execute under the guise of a trusted, digitally-signed Microsoft binary and evade many AV/EDR heuristics tuned to distrust unsigned executables.
Once loaded, the Sodinokibi/REvil encryptor created the registry key HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\BlackLivesMatter to store runtime configuration, including a per-victim public/private keypair generated via an embedded elliptic-curve scheme and the file extension to append to encrypted files. Files were encrypted using a Salsa20/AES hybrid scheme; the private key material needed for decryption was itself encrypted under a master public key controlled by the REvil operators and never transmitted off-host in plaintext, making the encryption cryptographically irreversible without cooperation from the attackers (or, ultimately, the FBI-obtained master key). Volume Shadow Copies were deleted and safe-mode boot recovery paths disabled to frustrate remediation.
The blast radius was compounded by Kaseya VSA's typical MSP deployment model: a single compromised on-premises VSA server often manages hundreds of downstream client endpoints across dozens of separate customer organizations, so encrypting one VSA console cascaded ransomware to every managed endpoint simultaneously. Kaseya identified roughly 50–60 MSPs running vulnerable on-premises VSA servers as the initial infection vector and proactively shut down its VSA SaaS infrastructure as a precaution, even though the SaaS environment itself was not confirmed compromised. Kaseya estimated 800–1,500 downstream businesses were ultimately encrypted; the highest-profile victim was Swedish supermarket chain Coop, which was forced to close roughly 800 stores for several days because point-of-sale systems were unusable, and several New Zealand schools also lost access to critical systems.
On July 5, 2021, a REvil-affiliated 'Happy Blog' post demanded $70 million in Bitcoin for a single universal decryptor capable of unlocking every victim encrypted in the campaign, while offering smaller individualized ransoms to specific organizations. Kaseya publicly stated it would not pay the ransom and worked with FireEye/Mandiant, the FBI, CISA, and Dutch researchers on incident response and a patch. On July 13, 2021, REvil's public-facing infrastructure — including its Tor payment portal and Happy Blog leak site — abruptly went offline; researchers assessed this reflected either a law-enforcement takedown, a voluntary shutdown by the operators fearing retaliation following high-level U.S.-Russia diplomatic pressure, or both. On July 21–23, 2021, Kaseya received a universal decryptor key from what it described as a 'trusted third party' — later confirmed via congressional testimony to be the FBI, which had obtained the REvil master decryption key through undisclosed means but withheld it from victims for roughly three weeks while weighing a disruption operation against REvil's infrastructure, a decision that drew significant criticism.
Attribution and downstream law enforcement action: Ukrainian national Yaroslav Vasinskyi was identified as a REvil affiliate responsible for deploying the ransomware in the Kaseya attack and was arrested in Poland on October 8, 2021, extradited to the United States, convicted, and sentenced on May 1, 2024 to 13 years 7 months in federal prison plus over $16 million in restitution. A second individual, Russian national Yevgeniy Polyanin, was separately charged for REvil-affiliate ransomware activity including Kaseya-related attacks; the U.S. Treasury and State Department additionally sanctioned REvil-linked infrastructure and offered a $10 million reward for information on REvil leadership. In November 2021, Russian authorities announced arrests of several individuals linked to REvil at the request of U.S. authorities, though the group's core leadership largely evaded lasting prosecution and REvil-derived tooling/personnel are assessed to have resurfaced in successor ransomware-as-a-service brands.
The incident remains a canonical case study in software-supply-chain risk for the MSP/RMM ecosystem: it demonstrated how a single vulnerable management platform can be weaponized to achieve mass simultaneous ransomware deployment across otherwise unrelated victim organizations that have no direct relationship with the attacker or even direct awareness that they run the vulnerable software, since the vulnerable server was operated by their MSP rather than by the victims themselves.
MITRE ATT&CK techniques used in TL-2026-1649
Discovery
T1018 Remote System Discovery; T1082 System Information Discovery
Lateral Movement
Defense Evasion
T1036.003 Rename Legitimate Utilities; T1036.005 Match Legitimate Resource Name or Location; T1070.004 File Deletion; T1140 Deobfuscate/Decode Files or Information
Execution
T1059.001 PowerShell; T1106 Native API
Command and Control
T1071.001 Web Protocols; T1090 Proxy
defense-impairment
T1112 Modify Registry; T1553.002 Code Signing; T1685 Disable or Modify Tools; T1685.005 Clear Windows Event Logs
Initial Access
T1190 Exploit Public-Facing Application; T1195 Supply Chain Compromise; T1199 Trusted Relationship
Impact
T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery; T1491 Defacement
Persistence
T1505 Server Software Component
Credential Access
stealth
Resource Development
Affected products and versions in Kaseya VSA Supply-Chain Ransomware Incident
- Kaseya — Virtual System Administrator (VSA) — on-premises
Vulnerable versions: 9.5.4 and earlier; 9.5.5; 9.5.6
Fixed in: 9.5.7a and later - Kaseya — Virtual System Administrator (VSA) — SaaS
Vulnerable versions: Proactively taken offline out of caution; not confirmed compromised
Fixed in: Restored after security hardening review
Remediation for Kaseya VSA Supply-Chain Ransomware Incident
Patches
- Kaseya VSA 9.5.5 — patches CVE-2021-30118 (Remote Code Execution)
- Kaseya VSA 9.5.6 — patches CVE-2021-30117 (SQL Injection), CVE-2021-30121 (Local File Inclusion), CVE-2021-30201 (XML External Entity)
- Kaseya VSA 9.5.7a — patches CVE-2021-30116 (Credentials Leak / Business Logic), CVE-2021-30119 (Cross-Site Scripting), CVE-2021-30120 (Two-Factor Authentication Bypass)
Immediate actions
- Shut down on-premises Kaseya VSA servers immediately and disconnect from the network until the vendor-confirmed patched build (VSA 9.5.7a or later) is applied
- Block all known campaign IOC IP addresses (18.223.199.234, 161.35.239.148, 35.226.94.113, 162.253.124.162) at perimeter firewalls and proxies
- Enable Windows Defender / EDR tamper protection to prevent malicious PowerShell from disabling real-time protection
- Search all endpoints for the files agent.crt, agent.exe, and mpsvc.dll and the registry key HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\BlackLivesMatter; isolate any host where they are found
- Run the Kaseya-published VSA Detection Tool / Compromise Detection Tool across all managed endpoints
- Preserve KaseyaEdgeServices logs in %ProgramData%\Kaseya\Log\ and full memory/disk images before remediation for forensics
Workarounds
- Take VSA on-premises servers fully offline until the certified-clean 9.5.7a (or later) build can be deployed
- Restrict VSA server inbound access to an allowlist of known-good management IP addresses only
- Disable automatic agent hot-fix/update push mechanisms until server integrity is confirmed
Longer-term hardening
- Deploy EDR with behavioral detection tuned to flag DLL side-loading via renamed/relocated Microsoft signed binaries (e.g., MsMpEng.exe launched from non-standard paths)
- Restrict and monitor RMM/VSA administrative interfaces behind VPN or dedicated admin network segmentation, never expose management consoles directly to the internet
- Implement application allowlisting to prevent execution of unsigned or unexpectedly-signed binaries from user-writable and temp directories
- Enforce MFA on all RMM platform accounts and require MFA for all customer-facing services delivered through MSP tooling
- Adopt a least-privilege model for MSP-to-customer trust relationships; segment MSP tooling network access from core customer production environments
CVEs associated with Kaseya VSA Supply-Chain Ransomware Incident
CVE-2021-30116, CVE-2021-30117, CVE-2021-30118, CVE-2021-30119, CVE-2021-30120, CVE-2021-30121, CVE-2021-30201
Weaknesses (CWE) in Kaseya VSA Supply-Chain Ransomware Incident
CWE-89, CWE-94, CWE-798, CWE-79, CWE-287, CWE-434, CWE-611, CWE-22
Timeline of Kaseya VSA Supply-Chain Ransomware Incident
- Dutch Institute for Vulnerability Disclosure (DIVD) researcher discovers six zero-day vulnerabilities in Kaseya VSA on-premises software during independent research.
- DIVD identifies a seventh related vulnerability (XML External Entity, later CVE-2021-30201) in the same VSA codebase.
- DIVD privately notifies Kaseya of the vulnerabilities; Kaseya begins a phased remediation and patch-development process with DIVD.
- Kaseya VSA 9.5.5 released, patching CVE-2021-30118 (Remote Code Execution).
- Kaseya VSA 9.5.6 released, patching CVE-2021-30117 (SQL Injection), CVE-2021-30121 (Local File Inclusion), and CVE-2021-30201 (XML External Entity); three critical flaws — including the authentication bypass — remained unpatched.
- Kaseya proactively shuts down its VSA SaaS servers and instructs all on-premises VSA customers to immediately take their servers offline pending investigation.
- REvil affiliates exploit the still-unpatched authentication bypass and chained flaws against internet-facing on-premises Kaseya VSA servers, push a trojanized 'Kaseya VSA Agent Hot-fix' (agent.crt) to managed endpoints, and detonate the Sodinokibi encryptor via MsMpEng.exe/mpsvc.dll DLL side-loading across roughly 60 MSPs and their downstream customers.
- CISA and the FBI publish joint guidance for MSPs and downstream customers affected by the Kaseya VSA supply-chain ransomware attack, recommending the Kaseya Compromise Detection Tool, MFA, and RMM network segmentation.
- REvil publishes a 'Happy Blog' post demanding $70 million in Bitcoin for a single universal decryptor covering all Kaseya-campaign victims, alongside smaller individualized ransom offers.
- Kaseya releases VSA 9.5.7a, patching the remaining critical vulnerabilities including CVE-2021-30116 (authentication bypass / credentials leak), CVE-2021-30119 (XSS), and CVE-2021-30120 (2FA bypass).
- REvil's public Tor payment portal and Happy Blog leak site abruptly go offline, coinciding with heightened U.S. diplomatic pressure on Russia; researchers assess a possible law-enforcement or voluntary shutdown.
- Kaseya receives a universal REvil decryption key from a 'trusted third party' (later confirmed to be the FBI) and distributes it to victims; Kaseya confirms it did not pay any ransom.
- Ukrainian national Yaroslav Vasinskyi, identified as the REvil affiliate who deployed the ransomware in the Kaseya attack, is arrested in Poland on a U.S. warrant.
- U.S. Treasury sanctions REvil-linked entities and DOJ unseals charges against Vasinskyi and Russian national Yevgeniy Polyanin for REvil ransomware activity, including the Kaseya campaign; State Department offers a $10 million reward for information on REvil leadership.
- Yaroslav Vasinskyi is sentenced to 13 years 7 months in federal prison and ordered to pay over $16 million in restitution for his role in the Kaseya VSA ransomware attack.
Sources cited for Kaseya VSA Supply-Chain Ransomware Incident
- Customer Advisory: Kaseya VSA Ransomware Incident
- CISA-FBI Guidance for MSPs and their Customers Affected by the Kaseya VSA Supply-Chain Ransomware Attack
- Kaseya Ransomware Attack: Guidance for Affected MSPs and their Customers
- CVE-2021-30116: Multiple Zero-Day Vulnerabilities in Kaseya VSA Exploited to Distribute Ransomware
- Kaseya patches VSA vulnerabilities used in REvil ransomware attack
- REvil ransomware hits 1,000+ companies in MSP supply-chain attack
- TTPs Used by REvil (Sodinokibi) Ransomware Gang in Kaseya MSP Supply-Chain Attack
- KASEYA Supply Chain Ransomware Attack — Technical Analysis of the REvil Payload
- Rapid Response: Mass MSP Ransomware Incident
- REvil Returns: Diving Deeper Into the Kaseya VSA Ransomware Attack
- Kaseya VSA Ransomware Attacks: Overview and Mitigation
- Kaseya VSA Downed by REvil in a Monumental Supply Chain Attack
- REvil Ransomware Attack on Kaseya VSA: What You Need to Know
- Kaseya VSA ransomware attack — Wikipedia
- DFIR Resources REvil Kaseya — YARA rules and IOC list
Threats related to Kaseya VSA Supply-Chain Ransomware Incident
Detection coverage for TL-2026-1649
As of 2026-07-23, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1649 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.