Kaseya VSA Supply-Chain Ransomware Incident — REvil/Sodinokibi Exploits CVE-2021-30116/30117/30118/30119/30120/30121 to Compromise 60 MSPs and 1,500+ Downstream Organizations — Threadlinqs Intelligence
As of 2026-07-23, Kaseya VSA Supply-Chain Ransomware Incident — REvil/Sodinokibi Exploits CVE-2021-30116/30117/30118/30119/30120/30121 to Compromise 60 MSPs and 1,500+ Downstream Organizations is a critical-severity ransomware threat attributed to REvil (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 21 indicators of compromise.
Threat ID: TL-2026-1649 · Severity: CRITICAL · CVSS: 9.8 · Status: RESOLVED · Category: RANSOMWARE
Attribution: REvil · Russia · FINANCIAL
The REvil/Sodinokibi ransomware-as-a-service operation chained multiple zero-day vulnerabilities (authentication bypass, SQL injection, arbitrary file upload, remote code execution) in Kaseya Virtual
On July 2, 2021, the REvil (Sodinokibi) ransomware-as-a-service affiliate operation launched one of the largest supply-chain ransomware attacks on record, exploiting Kaseya VSA — a widely deployed remote monitoring and management (RMM) platform used by managed service providers (MSPs) — to distribute ransomware to thousands of downstream customer endpoints in a single coordinated wave.
The intrusion began with exploitation of an authentication bypass vulnerability in the Kaseya VSA web interface (tracked publicly as part of the CVE-2021-30116/30117/30118/30119/30120/30121/30201 cluster first responsibly disclosed by the Dutch Institute for Vulnerability Disclosure, DIVD, on April 6, 2021). Attackers used the authentication bypass to obtain an authenticated session on internet-facing on-premises VSA servers, then chained an SQL injection flaw and an arbitrary file upload / code injection primitive to gain administrative control of the VSA management console without valid credentials.
From the compromised VSA server, the attackers abused the platform's own legitimate agent-update distribution mechanism to push a fraudulent update, disguised as a 'Kaseya VSA Agent Hot-fix,' to every endpoint the server managed — a textbook software-supply-chain trust abuse. The malicious update was delivered as an encoded file named agent.crt, decoded on-endpoint to agent.exe. Execution first invoked a PowerShell one-liner that disabled Windows Defender real-time monitoring, disabled Windows Error Recovery, and cleared event logs, then renamed certutil.exe to cert.exe to base64-decode the embedded payload while evading naive detection rules keyed on certutil.exe invocation.
agent.exe was signed with a certificate issued to 'PB03 TRANSPORT LTD' (subsequently revoked) and dropped two components into C:\Windows\: a deliberately outdated, legitimately signed copy of the Microsoft Defender executable (renamed MsMpEng.exe) and a malicious mpsvc.dll. Because the vulnerable, legitimate MsMpEng.exe loads mpsvc.dll from its own directory without integrity verification, launching MsMpEng.exe caused Windows itself to load and execute the REvil encryptor via DLL side-loading — a living-off-the-land technique that let the ransomware execute under the guise of a trusted, digitally-signed Microsoft binary and evade many AV/EDR heuristics tuned to distrust unsigned executables.
Once loaded, the Sodinokibi/REvil encryptor created the registry key HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\BlackLivesMatter to store runtime configuration, including a per-victim public/private keypair generated via an embedded elliptic-curve scheme and the file extension to append to encrypted files. Files were encrypted using a Salsa20/AES hybrid scheme; the private key material needed for decryption was itself encrypted under a master public key controlled by the REvil operators and never transmitted off-host in plaintext, making the encryption cryptographically irreversible without cooperation from the attackers (or, ultimately, the FBI-obtained master key). Volume Shadow Copies were deleted and safe-mode boot recovery paths disabled to frustrate remediation.
The blast radius was compounded by Kaseya VSA's typical MSP deployment model: a single compromised on-premises VSA server often manages hundreds of downstream client endpoints across dozens of separate customer organizations, so encrypting one VSA console cascaded ransomware to every managed endpoint simultaneously. Kaseya identified roughly 50–60 MSPs running vulnerable on-premises VSA servers as the initial infection vector and proactively shut down its VSA SaaS infrastructure as a precaution, even though the SaaS environment itself was not confirmed compromised. Kaseya estimated 800–1,500 downstream businesses were ultimately encrypted; the highest-profile victim was Swedish supermarket chain Coop, which was forced to close roughly 800 stores for several days because point-of-sale systems were unusable, and several New Z
Weaknesses (CWE)
CWE-89, CWE-94, CWE-798, CWE-79, CWE-287, CWE-434, CWE-611, CWE-22
Target sectors: msp, retail, education, government administration, finance, health, technology, manufacturing
Target regions: North America, Europe, Oceania, Africa, Worldwide
Detections & IOCs
As of 2026-07-24, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 21 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, CRITICAL, threat intelligence, cybersecurity, CVE-2021-30116, CVE-2021-30117, CVE-2021-30118, CVE-2021-30119, CVE-2021-30120, CVE-2021-30121, CVE-2021-30201, T1190, T1195, T1199, T1059.001, T1106, T1574.002, T1505, T1574.002, T1562.001, T1036.003