{"id":7829,"date":"2021-07-05T10:23:25","date_gmt":"2021-07-05T14:23:25","guid":{"rendered":"https:\/\/www.technewsday.com\/?p=7829"},"modified":"2021-07-23T13:55:46","modified_gmt":"2021-07-23T17:55:46","slug":"revil-attacked-1000-companies-in-supply-chain-attack","status":"publish","type":"post","link":"https:\/\/technewsday.com\/staging\/revil-attacked-1000-companies-in-supply-chain-attack\/","title":{"rendered":"REvil Attacked 1,000+ Companies In Supply-Chain Attack"},"content":{"rendered":"\n<p>A massive ransomware attack by REvil has affected several managed service providers and over a thousand of their customers through a reported Kaseya supply chain attack, which was allegedly committed by the REvil ransomware gang alias Sodinokibi.<\/p>\n\n\n\n<p>Kaseya VSA is a cloud-based MSP platform that enables vendors to perform patch management and client monitoring for their customers.<\/p>\n\n\n\n<p>John Hammond of Huntress Labs mentioned that all affected MSPs use Kaseya VSA and that they have evidence that their customers are also encrypted.<\/p>\n\n\n\n<p>Kaseya has posted a security advisory on its helpdesk page warning all VSA customers to immediately shut down their VSA server to prevent the spread of the attack while investigations are ongoing.<\/p>\n\n\n\n<p>Most large-scale ransomware attacks are carried out late at night over the weekend when less staff are available to monitor the network.<\/p>\n\n\n\n<p>Threat actors probably planned the timing to coincide with the Fourth of July weekend in the U.S., where it is common for employees to have a shorter working day before the holidays.<\/p>\n\n\n\n<p>The ransomware gang demanded a ransom of $5 million in exchange for a decryptor from one of the samples.<\/p>\n\n\n\n<p>MSP customers affected by the attack received a significantly lower ransom of $44,999.<\/p>\n\n\n\n<p>Although REvil is known to steal data before the ransomware is deployed and devices are encrypted, it is not known whether the attackers have exfiltrated any files.<\/p>\n\n\n<p>For more information, read the <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/revil-ransomware-hits-1-000-plus-companies-in-msp-supply-chain-attack\/\" target=\"_blank\" rel=\"noopener\">original story<\/a> in Bleeping Computer.<\/p>","protected":false},"excerpt":{"rendered":"<p>A massive ransomware attack by REvil has affected several managed service providers and over a thousand of their customers through a reported Kaseya supply chain attack.<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[16],"tags":[],"class_list":["post-7829","post","type-post","status-publish","format-standard","hentry","category-security"],"acf":[],"_links":{"self":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/7829","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/comments?post=7829"}],"version-history":[{"count":3,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/7829\/revisions"}],"predecessor-version":[{"id":7868,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/7829\/revisions\/7868"}],"wp:attachment":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/media?parent=7829"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/categories?post=7829"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/tags?post=7829"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}