A group tools of remote management hackers breached the infrastructure of three MSP companies, with the aim of spreading ransomware to the companies' customer systems. To achieve this, the hackers exploited , namely Webroot SecureAnywhere.
MSP companies provide IT and support services to companies and organizations around the world. The ransomware infection was detected yesterday.
Kyle Hanslovan, co-founder and CEO of Huntress Lab, offered assistance to some of these MSPs, affected by the attack, to investigate the incidents.
According to Hanslovan, hackers were able to breach MSP companies using exposed RDP (Remote Desktop Endpoints), elevated privileges on compromised systems, and AV products, such as ESET and Webroot.
The hackers then used Webroot SecureAnywhere, the software that MSP companies use to remotely their customers' networks.

With Webroot SecureAnywhere, hackers execute a Powershell script on remote networks. However, this script actually downloads and installs Sodinokibi ransomware.
Hanslovan said the hackers breached at least three MSPs in this way. Some have suggested that the hackers may have also used the Kaseya VSA remote management console to carry out the attack. However, this has not been officially confirmed.
Two of the three companies affected said the breach only affected computers running Webroot. Hanslovan said: "Given that Webroot allows administrators to remotely download and execute files on their customers' computers, this attack could be considered an 'attack vector', where hackers gain access to a computer or network and can install malware, etc.
Shortly after being notified of the attack, Webroot enabled two-factor authentication (2FA) for SecureAnywhere accounts, in an effort to prevent hackers from using other compromised accounts and deploying new ransomware.
Under normal circumstances, SecureAnywhere supports 2FA, but the feature is not enabled by default.
Sodinokibi ransomware is a relatively new ransomware. It was first detected in late April. At the time, the hacker was exploiting a vulnerability in Oracle WebLogic server and spreading the ransomware across corporate networks.
The current attack is the second largest attack on MSP companies, where hackers used the companies' own remote management tools.
