HOME

TheInfoList



OR:

On 2 July 2021, a number of
managed service provider Managed services is the practice of outsourcing the responsibility for maintaining, and anticipating need for, a range of processes and functions, ostensibly for the purpose of improved operations and reduced budgetary expenditures through the re ...
s (MSPs) and their customers became victims of a
ransomware Ransomware is a type of malware from cryptovirology that threatens to publish the victim's personal data or permanently block access to it unless a ransom is paid off. While some simple ransomware may lock the system without damaging any files, ...
attack perpetrated by the
REvil REvil (Ransomware Evil; also known as Sodinokibi) was a Russia-based or Russian-speaking private ransomware-as-a-service (RaaS) operation. After an attack, REvil would threaten to publish the information on their page ''Happy Blog'' unless the ra ...
group, causing widespread downtime for over 1,000 companies.


Company

Kaseya Limited is an American software company founded in 2001. It develops software for managing
networks Network, networking and networked may refer to: Science and technology * Network theory, the study of graphs as a representation of relations between discrete objects * Network science, an academic field that studies complex networks Mathematics ...
,
systems A system is a group of interacting or interrelated elements that act according to a set of rules to form a unified whole. A system, surrounded and influenced by its environment, is described by its boundaries, structure and purpose and express ...
, and
information technology Information technology (IT) is the use of computers to create, process, store, retrieve, and exchange all kinds of data . and information. IT forms part of information and communications technology (ICT). An information technology system (I ...
infrastructure. Owned by
Insight Partners Insight Partners (previously Insight Venture Partners) is an American venture capital and private equity firm based in New York City. The firm invests in growth-stage technology, software and Internet businesses. History Insight Partners was fo ...
, Kaseya is headquartered in
Miami, Florida Miami ( ), officially the City of Miami, known as "the 305", "The Magic City", and "Gateway to the Americas", is a East Coast of the United States, coastal metropolis and the County seat, county seat of Miami-Dade County, Florida, Miami-Dade C ...
with branch locations across the US, Europe, and Asia Pacific. Since its founding in 2000, it has acquired 13 companies, which have in most cases continued to operate as their own brands (under the "a Kaseya company" tagline), including Unitrends.


Timeline and impact

Researchers of the Dutch Institute for Vulnerability Disclosure identified the first vulnerabilities in the software on April 1. They warned Kaseya and worked together with company experts to solve four of the seven reported vulnerabilities. Despite the efforts, Kaseya could not patch all the bugs in time. The source of the outbreak was identified within hours to be VSA (Virtual System Administrator), a Remote monitoring and management software package developed by Kaseya. An authentication bypass
vulnerability Vulnerability refers to "the quality or state of being exposed to the possibility of being attacked or harmed, either physically or emotionally." A window of vulnerability (WOV) is a time frame within which defensive measures are diminished, com ...
in the software allowed attackers to compromise VSA and distribute a malicious payload through hosts managed by the software, amplifying the reach of the attack. In response, the company shut down its VSA
cloud In meteorology, a cloud is an aerosol consisting of a visible mass of miniature liquid droplets, frozen crystals, or other particles suspended in the atmosphere of a planetary body or similar space. Water or various other chemicals may co ...
and
SaaS Software as a service (SaaS ) is a software licensing and delivery model in which software is licensed on a subscription basis and is centrally hosted. SaaS is also known as "on-demand software" and Web-based/Web-hosted software. SaaS is con ...
servers and issued a security advisory to any customers, including those with
on-premises On-premises software (abbreviated to on-prem, and incorrectly referred to as on-premise) is installed and runs on computers on the premises of the person or organization using the software, rather than at a remote facility such as a server farm ...
deployments of VSA. Initial reports of companies affected by the incident include Norwegian financial software developer
Visma Visma is a privately held company headquartered in Oslo, Norway, that provides business software and IT related development and consultancy. The company is majority owned by Hg, a private equity firm. The company was formed in 1996 in Norway, t ...
, who manages some systems for Swedish supermarket chain
Coop Coop, COOP, Co-op, or ''variation'', most often refers to: * A chicken coop or other enclosure * Cooperative or co-operative ("co-op"), an association of persons who cooperate for their mutual social, economic, and cultural benefit ** Housing ...
. The supermarket chain had to close down its 800 stores for almost a week, some in small villages without any other food shop. They did not pay ransom, but rebuilt their systems from scratch after waiting for an update from Kaseya. The
REvil REvil (Ransomware Evil; also known as Sodinokibi) was a Russia-based or Russian-speaking private ransomware-as-a-service (RaaS) operation. After an attack, REvil would threaten to publish the information on their page ''Happy Blog'' unless the ra ...
ransomware gang officially took credit for the attack and claimed to have encrypted more than one million systems during the incident. They initially asked for a $70 million ransom payment to release a universal decryptor to unlock all affected systems. On July 5, Kaseya said that between 800 and 1,500 downstream businesses were impacted in the attack.
Marcus Hutchins Marcus Hutchins (born 1994), also known online as MalwareTech, is a British computer security researcher known for stopping the WannaCry ransomware attack. He is employed by cybersecurity firm Kryptos Logic. Hutchins is from Ilfracombe in Dev ...
criticized the assessment that the impact of the Kaseya attack was larger than
WannaCry The WannaCry ransomware attack was a worldwide cyberattack in May 2017 by the WannaCry ransomware cryptoworm, which targeted computers running the Microsoft Windows operating system by encrypting data and demanding ransom payments in the Bi ...
, citing difficulties in measuring the exact impact. After a 9 July 2021 phone call between United States president Joe Biden and Russian president
Vladimir Putin Vladimir Vladimirovich Putin; (born 7 October 1952) is a Russian politician and former intelligence officer who holds the office of president of Russia. Putin has served continuously as president or prime minister since 1999: as prime min ...
, Biden told the press, "I made it very clear to him that the United States expects when a ransomware operation is coming from his soil even though it’s not sponsored by the state, we expect them to act if we give them enough information to act on who that is." Biden later added that the United States would take the group's servers down if Putin did not. On 13 July 2021, REvil websites and other infrastructure vanished from the internet. On 23 July 2021, Kaseya announced it had received a universal decryptor tool for the REvil-encrypted files from an unnamed "trusted third party" and was helping victims restore their files. On 8 November 2021, the
United States Department of Justice The United States Department of Justice (DOJ), also known as the Justice Department, is a federal executive department of the United States government tasked with the enforcement of federal law and administration of justice in the United State ...
unsealed indictments against Ukrainian national Yaroslav Vasinskyi and Russian national Yevgeniy Polyanin. Vasinskyi was charged with conducting ransomware attacks against multiple victims including Kaseya, and was arrested in Poland on 8 October. Polyanin was charged with conducting ransomware attacks against multiple victims including Texas businesses and government entities. The Department worked with the
National Police of Ukraine The National Police of Ukraine ( uk, Націона́льна полі́ція Украї́ни, translit=Natsionálʹna polítsiya Ukrayíny, ; , NPU), often simply referred to as the ( uk, Поліція, lit=Police, label=none), is the nation ...
for the charges, and also announced the seizure of $6.1 million tied to ransomware payments. If convicted on all charges, Vasinskyi faces a maximum penalty of 115 years in prison, and Polyanin 145 years in prison.


References

{{Hacking in the 2020s 2021 in computing