Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Kaseya obtained a universal decryptor for REvil ransomware attack
Security affairs ^ | 7-23-21 | Pierluigi Paganini

Posted on 07/23/2021 4:44:10 PM PDT by dynachrome

Earlier this month, a massive supply chain attack conducted by the REvil ransomware gang hit the cloud-based managed service provider platform Kaseya, impacting both other MSPs using its VSA software and their customers.

For the initial attack vector, REvil operators exploited an authentication bypass zero-day (CVE-2021-30116) in the web interface of the Kaseya VSA server to gain an authenticated session. Then, the attackers uploaded the payload and executed a command via SQL injection to deploy the malicious updates. Ransomware operators initially asked the owners of systems infected in this campaign $44,999 worth of Bitcoin. Later, they changed tactics and demanded a single massive ransom of $70 million from all of the victims. Kaseya now announced to have received a universal decryptor that allows victims of the ransomware attack to recover their files for free.

Kaseya now announced to have received by trusted third-party a universal decryptor that allows victims of the ransomware attack to recover their files for free.

The software firm tested the tool and verified that it successfully recover the files encrypted with the REvil ransomware, now the company is providing the tool to its customers to help them to restore the encrypted systems. The company confirmed that fewer than 60 of its customers and less than 1,500 businesses have been impacted by the attack.

Now the availability of a universal decryptor made the headline, but the company did not reveal if it has obtained the tool after the payment of the ransom.

We cannot exclude that the REvil operators have released the decryptor for free to avoid the pressure of the authorities and law enforcement.

(Excerpt) Read more at securityaffairs.co ...


TOPICS: Business/Economy; Computers/Internet
KEYWORDS: decrypted; kaseya; ransomware
The ransom was paid or someone talked.
1 posted on 07/23/2021 4:44:10 PM PDT by dynachrome
[ Post Reply | Private Reply | View Replies]

To: dynachrome

Or the ransomware hackers were found and liquidated after yielding the decrypting application under “enhanced interrogation” techniques.


2 posted on 07/23/2021 5:07:52 PM PDT by E. Pluribus Unum ("Communism is not love. Communism is a hammer which we use to crush the enemy." ― Mao Zedong)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dynachrome

“or someone talked.”

or MADE to talk ...


3 posted on 07/23/2021 8:35:51 PM PDT by catnipman (Cat Nipman: Vote Republican in 2012 and only be called racist one more time!)
[ Post Reply | Private Reply | To 1 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson