REvil exploited a zero-day in on-premises Kaseya VSA servers to launch a supply-chain ransomware attack that spread through managed service providers and into downstream customer networks, ultimately affecting about 60 MSPs and roughly 1,500 businesses. Researchers reported the attackers used VSA’s privileged access to push a malicious script, attempted to disable Microsoft Defender, abused certutil, and side-loaded a malicious DLL using a legitimate MsMpEng.exe binary, enabling rapid encryption across victim environments. The gang demanded $70 million for a universal decryptor, while defenders published indicators of compromise and detection guidance tied to behaviors such as DLL sideloading and suspicious PowerShell and Windows event activity.
A universal decryptor for the Kaseya-related campaign later emerged, but reporting showed the FBI had secretly obtained the key and withheld it for 19 days while weighing a broader operation against the Russia-linked REvil gang. During that delay, many victims restored from backups or absorbed recovery costs before Kaseya received the key on July 21 and worked with Emsisoft to release a decryptor the next day; Bitdefender later published a broader tool for some earlier REvil victims. The campaign-specific key was subsequently leaked on a hacking forum and verified by researchers, reinforcing that it worked for the Kaseya incident but was not a master key for all REvil infections.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
12 events from the most recent confirmed update back to the earliest known activity.
On July 22, 2021, Kaseya obtained a universal decryption key or decryptor for the attack from a mysterious trusted third party and began distributing it to affected customers. Reporting said customers were required to sign a non-disclosure agreement before receiving it.
On July 21, 2021, the FBI provided Kaseya with a digital decryption key it had obtained through access to REvil servers. The bureau had withheld the key for about 19 days while considering a broader operation against the ransomware gang.
As news of the attack broke on July 3, 2021, Kaseya urged VSA users to shut down their servers to prevent compromise. Around the same time, Kaseya said fewer than 40 customers were directly affected, though downstream impact was believed to be much larger.
On July 2, 2021, REvil exploited a zero-day vulnerability in Kaseya VSA to distribute ransomware through managed service providers and their downstream customers. The attack affected dozens of direct Kaseya customers and ultimately hundreds to roughly 1,500 businesses.
REvil's platform, including its Tor payment sites and infrastructure, went offline in mid-July 2021 without U.S. government intervention. The outage disrupted victims' ability to pay and derailed a planned U.S. disruption operation against the gang.
In June 2021, REvil attacked JBS, temporarily disrupting some operations in Australia, Canada, and the United States. The incident was cited as part of REvil's broader activity before the Kaseya attack.
After disappearing, REvil reappeared, rebuilt its platform, and resumed activity. By the time of the report, at least eight new victims had been logged.
Bitdefender later released a universal decryptor for systems encrypted by REvil before July 13, the date REvil's platform went offline. The company said it received the key from a law enforcement partner that was not the FBI.
Researchers including BleepingComputer, Emsisoft, and Flashpoint confirmed the leaked key successfully decrypted files from the Kaseya-related REvil campaign but did not work on other REvil samples. This established that the leak was campaign-specific rather than a universal master key for all REvil victims.
A post on a hacking forum linked to a GitHub-hosted screenshot showing a base64-encoded REvil decryptor key, giving researchers their first direct view of the Kaseya campaign's universal key. Flashpoint and others investigated whether the posted key could decrypt Kaseya-related REvil victims.
The day after receiving the key, Kaseya worked with Emsisoft to create and release a decryptor for affected victims. Emsisoft said it extracted the key, built the tool, and tested it within minutes.
Following the Kaseya-related disruption, Swedish grocery chain Coop closed about 700 stores for six days. Analysts estimated the shutdown likely cost the company millions of dollars in lost business.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
washingtonpost.com
Open sourcembsd.jp
Open sourcebleepingcomputer.com
Open sourcembsd.jp
Open sourceflashpoint-intel.com
Open sourcesplunk.com
Open sourcesymantec-enterprise-blogs.security.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.