HomeSecurityKaseya REvil ransomware: Over 1,500 companies affected

Kaseya REvil ransomware: Over 1,500 companies affected

Software company Kaseya has confirmed that approximately 1,500 businesses were affected by an exploit in the company's remote device management software, which was used to spread the REvil ransomware.

Kaseya REvil ransomware

The attackers carried out a supply chain ransomware attack, exploiting a vulnerability in Kaseya's VSA software, which is used by many MSPs. This affected both themselves and their customers.

“To date, we are aware of fewer than 60 Kaseya customers using the VSA product who were directly compromised by this attack. As many of these customers provide IT services to many other companies, we estimate that a total of approximately 1,500 companies may have been impacted. We have not found evidence that any of our SaaS customers have been compromised,” Kaseya said.

See also: The group behind Trickbot is linked to the Diavol ransomware

The attackers exploited a vulnerability in Kaseya's VSA software, a remote monitoring and management software used to manage endpoints such as computers, servers and cash registers. It is also used to manage and fix vulnerabilities. The company had been notified of the vulnerability by researchers and had created a patch, but had not yet released it to its customers.

On Sunday, the REvil ransomware gang demanded $70 million for the provision of a decryption tool, which would unlock the systems of all victims.

Learn more: REvil ransomware Kaseya: Hackers demand $70 million to decrypt all systems

Kaseya REvil ransomware: Over 1,500 companies affected

Kaseya said that no other of the company's products have been compromised.

However, although VSA's software-as-a-service (SaaS) line was not affected, the servers were taken offline.

A patch for customers running VSA should be available 24 hours after the company's SaaS servers are restored, which it estimates will happen today, July 6, Kaseya said in an update.

See also: Kaseya Ransomware Attack: Biden Calls on Affected Companies to Report It

The company worked with the FBI and CISA to investigate some key elements before restoring the systems.

Kaseya has also released a new free detection toolthat customers can use to monitor their networks and computers. Kaseya's tool looks for indicators of compromise, data encryption, and the REVil ransomware gang's ransom note.

Kaseya urges customers to keep VSA servers offline until it is safe to proceed with recovery efforts.

Source: ZDNet

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS