REvil affiliates exploited four zero-day flaws in on-premises Kaseya VSA servers to turn a trusted remote management platform into a ransomware delivery channel for managed service providers and their customers. The attack chain reportedly included an authentication bypass, unrestricted file upload, CSRF bypass, and command injection, allowing attackers to upload malicious ASP code and push ransomware through VSA with administrator-level access. Researchers said the campaign abused Kaseya-mandated antivirus exclusions, used agentmon.exe to launch malicious commands, decoded payloads with a renamed certutil, and side-loaded a malicious DLL through a signed dropper and an outdated Microsoft Defender binary while disabling multiple Defender protections.
The supply-chain attack encrypted local, removable, and mapped network drives across downstream environments, affecting about 60 MSPs and roughly 1,500 businesses, though REvil claimed a far larger device count and demanded $70 million for a universal decryptor. Red Canary said it detected the activity before the vulnerabilities were publicly known by spotting behavioral indicators such as Defender tampering and registry changes tied to REvil, then used containment actions including endpoint isolation and hash banning across multiple customer environments. Kaseya later patched the flaws in version 9.5.7a and subsequently obtained a universal decryptor from a trusted third party, which it distributed to victims as the FBI and DOJ continued investigating the incident.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
13 events from the most recent confirmed update back to the earliest known activity.
Kaseya announced on July 22, 2021 that it had obtained a universal decryptor for victims of the July 2 REvil attack from a trusted third party and began distributing it to affected customers. Emsisoft said it validated the decryptor and would assist with recovery efforts.
On July 11, 2021, Kaseya released patch 9.5.7a (9.5.7.2994) to address the vulnerabilities exploited in the REvil attack. Reporting later described the incident as involving four zero-day flaws in Kaseya VSA.
On 2021-07-09, the CVE record for CVE-2021-30116 was published, describing a critical Kaseya VSA vulnerability involving unauthenticated credential leakage via dl.asp and a business logic flaw that could yield a sessionId for further semi-authenticated attacks. The record states the issue was exploited in the wild in July 2021 and credits Wietse Boonstra of DIVD, with additional research by Frank Breedijk.
On July 5, 2021, Truesec said it contacted Kaseya with a detailed technical write-up and forensic evidence describing the four-flaw exploit chain used against VSA servers. The chain included authentication bypass, unrestricted file upload, CSRF bypass, and code injection issues.
A little more than six hours after the initial threat on July 2, 2021, Red Canary sent a bulletin with its findings to all customers. By then, its threat research team had already reverse engineered the ransomware payload and started drafting findings.
On July 2, 2021, Huntress Labs said it had tracked the REvil Kaseya VSA supply-chain attack across 20 managed service providers, with more than 1,000 downstream businesses encrypted. The report marked a major early estimate of the campaign's scale beyond Kaseya's directly affected on-premises customers.
On July 2, 2021, Kaseya urged all VSA customers to immediately take their servers offline and shut down its own cloud infrastructure in an effort to halt malicious updates and remove the attackers from its systems. CISA also said it was investigating the incident.
About an hour after Red Canary's first detections on July 2, 2021, initial public reporting about the incident appeared on Reddit and Twitter. Kaseya formally acknowledged the incidents about two and a half hours after Red Canary's first detections.
Roughly two hours after the initial threat on July 2, 2021, Red Canary enabled Automate for the affected legacy customer group and began banning hashes, collecting forensic packages, and isolating endpoints. These actions were used to contain the ransomware activity across impacted systems.
On July 2, 2021, Red Canary saw the same malicious behavior appear in a second customer environment 23 minutes after the first threat and in a third roughly an hour after the initial activity. Similar detections and response actions continued across two more customers and dozens of endpoints over the following three days.
Less than an hour after the initial activity on July 2, 2021, Red Canary observed REvil-associated registry modifications and, within 12 minutes of the threat, proactively contacted the first affected customer. The customer was in a legacy group without Red Canary Automate access.
At about 1 PM ET on July 2, 2021, Red Canary observed Kaseya VSA agentmon.exe launching malicious commands, including disabling Microsoft Defender protections and using a renamed certutil binary to decode a payload. Within minutes, its detection engineering team began investigating the activity.
On July 2, 2021, a REvil affiliate exploited zero-day vulnerabilities in on-premises Kaseya VSA servers and used the platform to push a malicious update to MSP customers and enterprise users, leading to mass ransomware deployment on managed endpoints.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
14 references tracked. Mallory keeps watching after this page renders.
cve.mitre.org
Open sourcenews.sophos.com
Open sourcehuntress.com
Open sourceredcanary.com
Open sourceblog.truesec.com
Open sourcedoublepulsar.com
Open sourcebleepingcomputer.com
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.