In a post on the REvil dark web blog, the gang takes credit for the Kaseya attack, claims it infected 1M+ systems, and demands $70M in bitcoin for the decryptor
The REvil ransomware gang is asking for a $70 million ransom payment to publish a universal decryptor that can unlock …
The Record Catalin Cimpanu
Context & Ripple Effects
The immediate backdrop was REvil's use of a malicious Kaseya software update against managed service providers and their customers. Its demand for a single decryptor turns that distribution path into leverage over a far wider set of affected organizations.
The episode's arc later shifted from the ransom demand to Kaseya's announcement that it had obtained a universal decryptor and begun helping customers recover. That makes the initial claim significant as a test of how quickly a software supplier can restore customers after a compromised update.
First-order effects
- REvil puts Kaseya and the companies reached through its management software under pressure to regain access to affected systems, while seeking $70 million for one decryptor.
- Kaseya becomes the recovery intermediary for affected customers because the proposed decryptor is designed to work across the incident rather than for a single victim.
Second-order effects
- Managed service providers hit through Kaseya must coordinate recovery with both Kaseya and their own customers, concentrating operational pressure on the supplier's response.
- Kaseya's later access to a universal decryptor shifts the immediate priority from negotiating individual recoveries to distributing a common recovery tool to customers.
Third-order effects
- The incident illustrates how compromise of an IT management update can concentrate ransomware exposure across service providers and their customer bases, making supplier security and recovery capacity a shared dependency.
- If attackers continue targeting centrally managed software, ransomware disruption will increasingly be organized around software distribution channels rather than isolated victim networks.
The trend: Ransomware groups are targeting centralized software-management channels to amplify both the scale of disruption and the leverage of a single extortion demand.
Related: Kaseya · REvil claims responsibility for the Kaseya attack · Kaseya obtains a universal REvil decryptor · REvil forced offline in multi-country operation
Related Coverage
- Rapid Response: Mass MSP Ransomware Incident Huntress Blog · John Hammond
- REvil ransomware hits 1,000+ companies in MSP supply-chain attack BleepingComputer · Lawrence Abrams
- View article us-cert.cisa.gov
- View article Sky News
- View article Decrypt
- Scale, details of massive ransomware attack emerge Politico
- REvil ransomware attack against MSPs and its clients around the world Securelist · Kaspersky
- Kaseya ransomware supply chain attack: What you need to know ZDNet · Charlie Osborne
- REvil ransomware hackers demand $70 million — businesses worldwide go down Laptop Mag · Jason England
- Independence Day: REvil uses supply chain exploit to attack hundreds of businesses Sophos News
- Statement by Deputy National Security Advisor for Cyber and Emerging Technology Anne Neuberger on Reporting Kaseya Compromises The White House
- View article Neowin
- View article MUO
- IT for service providers biz Kaseya defers decision about SaaS restoration following supply chain attack The Register · Simon Sharwood
- REvil Demands $70M in Bitcoin After Ransomware Attack Crypto Briefing · Nivesh Rustgi
- $70 Million Demanded As REvil Ransomware Attackers Claim 1 Million Systems Hit Forbes · Davey Winder
- REvil's Kaseya attack might be the largest ransomware attack in history Candid.Technology · Yadullah Abidi
- REvil ransomware gang demanded $70M for universal decryptor for Kaseya victims Security Affairs · Pierluigi Paganini
- Kaseya Cyberattack: End Customers Ransomed, MSPs Spared CRN · Michael Novinson
- REvil gang exploited a zero-day in the Kaseya supply chain attack Security Affairs · Pierluigi Paganini
- Sodinokibi hackers demand $70 mln to restore data held by companies hit in Kaseya cyberattack DataBreaches.net
- Supply-chain attack on Kaseya remote management software targets MSPs CSO · Lucian Constantin
- FBI Statement on Kaseya Ransomware Attack Federal Bureau of Investigation
- REvil is increasing ransoms for Kaseya ransomware attack victims BleepingComputer · Lawrence Abrams
- Apple-backed ride-hailing app ‘Didi’ is removed from App Store in China after U.S IPO iThinkDifferent · Rida Imran
- REvil's humungous $70M Kaseya ransomware attack, explained TNW · Abhimanyu Ghoshal
- 5 Takeaways On Kaseya Cyberattack From CEO Fred Voccola CRN · Michael Novinson
- Biden announces investigation into international ransomware attack The Guardian
- Swiss supermarket chain offline as REvil campaign targets Kaseya VSA SiliconANGLE · Duncan Riley
- Biden Launches Federal Probe Into International Ransomware Attack That Hit 1,000+ Companies Gizmodo · Alyse Stanley
- Cyber attack on US businesses through Kaseya software to be investigated for Russia links ABC
- Holiday-Weekend Ransomware Attack Leaves Companies Scrambling Voice of America
- Russia-based hackers breach more than 1,000 businesses Axios
- Gang behind huge cyber-attack demands $70m in Bitcoin BBC
- Swedish Supermarket Chain Hit by Massive Cyberattack Softpedia News · George Dascalu
- Ransomware Hackers Demand $70 Million In Bitcoin, Claim Massive U.S. Attack As Biden Investigates Possible Russian Involvement Forbes · Robert Hart
- Swedish Coop supermarkets shut due to US ransomware cyber-attack BBC · Joe Tidy
- Coop supermarket closes hundreds of stores after Kaseya supply chain ransomware attack Security Affairs · Pierluigi Paganini
- Massive ransomware attack potentially hit 1,000 businesses Livemint
- Cyber attack against U.S. IT provider forces Swedish chain to close 800 stores Reuters · Johan Ahlander
Discussion
-
@vxunderground
Vx-Underground
on x
REvil has named its price. $70,000,000 USD in Bitcoin. Attached image is directly from REvils website: https://twitter.com/...
-
@pwnallthethings
@pwnallthethings
on x
So if you want a spicy take, although the direct impact of this is relatively small /so far/, its strategic impact dwarfs everything else in cybersecurity this year by a margin including Exchange hack, Colonial pipeline hack, and maybe even SolarWinds. https://twitter.com/...
-
@campuscodi
Catalin Cimpanu
on x
Why would REvil pull such a brash attack right after the Colonial and JBS attacks and the political mess/fallouts from those incidents? -Wouldn't this attack confirm that REvil had some sort of approval from a RU agency before doing something this destructive?
-
@campuscodi
Catalin Cimpanu
on x
Was the timing of the attack on the July 4 weekend a decision made for political reasons or was it REvil's typical modus operandi to hit over big western holiday breaks (which they have done many times before)? -Why are they asking a payment for an universal decrypter?
-
@campuscodi
Catalin Cimpanu
on x
Did they realize that negotiating ransoms with thousands of companies at the same time is not worth the effort? -Will that universal decrytper even work, or are companies going to encounter bugs with large files? -Will Kaseya even consider paying?
-
@campuscodi
Catalin Cimpanu
on x
Some questions in regards to the Kaseya incident: -How did REvil learn of the VSA exploit? -Did they have access to Kaseya's vulnerability disclosure systems? -Where they provided the exploit by a 3rd-party? -Was that 3rd-party an RU intelligence agency or exploit broker?
-
@campuscodi
Catalin Cimpanu
on x
Apparently, this would be one gigantic discount. So nice of REvil... 😅 https://twitter.com/...
-
@campuscodi
Catalin Cimpanu
on x
Scoop/breaking: The REvil ransomware gang is asking for $70 million to publish a universal decryptor that can unlock all computers locked during the Kaseya incident https://therecord.media/... https://twitter.com/...
-
@campuscodi
Catalin Cimpanu
on x
In a message posted on their dark web blog, the REvil gang officially took credit for the attack for the first time and claimed they locked more than one million systems during the Kaseya incident.
-
@bdsams
Brad Sams
on x
The legitimacy of BTC would be vastly improved if it wasn't universally associated with ransom payments. https://twitter.com/...
-
@ncweaver
Nicholas Weaver
on x
This is possibly even MORE disturbing than a supply chain attack, because it brings up the possibility at least of a “lab leak”, the ransomware gang learning of the exploit itself OR at least plans to patch it. Leaks like this don't affect a single vendor. https://twitter.com/...
-
@serghei
@serghei
on x
“Although the scale of this incident may make it so that we are unable to respond to each victim individually, all information we receive will be useful in countering this threat.” 👀 https://twitter.com/...
-
@0xdude
Victor Gevers
on x
During the last 48 hours, the number of Kaseya VSA instances that are reachable from the internet has dropped from over 2.200 to less than 140 in our last scan today. https://csirt.divd.nl/...
-
@esetresearch
@esetresearch
on x
#ESETresearch responded to ransomware deployed as supply-chain attack against #Kaseya VSA users attributed to #REvil beginning Friday afternoon EDT (US)/evening CEST (Europe). Detection was added for Win32/Filecoder.Sodinokibi.N on Friday shortly after.https://www.welivesecurity.…
-
@uscert_gov
Us-Cert
on x
.@CISAgov and @FBI strongly recommend MSPs and #MSP customers affected by the Kaseya VSA supply-chain #ransomware attack take immediate action. See https://us-cert.cisa.gov/... for recommendations. #Cybersecurity #InfoSec #Ransomware
-
@kaseyacorp
@kaseyacorp
on x
Updates Regarding VSA Security Incident July 4, 2021 - 10:00 AM EDT Next Update will be published July 4, 2021, in the early afternoon EDT https://www.kaseya.com/...
-
@_johnhammond
John Hammond
on x
If you haven't seen it, Kaseya has now shared their own detection tool. From their report, “The new Compromise Detection Tool was rolled out last night to almost 900 customers who requested the tool.” https://helpdesk.kaseya.com/ ...
-
@raj_samani
Raj Samani
on x
Some small respite for victims of the Kaseya attack - “REvil representatives have told victims that they only encrypted networks, and nothing more. This means that REvil likely did not steal any of the victims' data” https://www.bleepingcomputer.com/ ... #ransomware #malware #cyb…
-
@bad_packets
Bad Packets Llc
on x
@FBI The vendor says, “Only a very small percentage of our customers were affected - currently estimated at fewer than 40 worldwide.” The FBI says, “Although the scale of this incident may make it so that we are unable to respond to each victim individually.” 🤔
-
@fbi
@fbi
on x
#FBI Statement on Kaseya Ransomware Attack @CISAgov https://www.fbi.gov/... https://twitter.com/...
-
@randahabib
Randa Habib
on x
President Joe Biden said he has directed U.S. intelligence agencies to investigate who was behind a sophisticated ransomware attack that hit hundreds of American businesses and led to suspicions of Russian gang involvement. https://www.reuters.com/...
-
@gossithedog
Kevin Beaumont
on x
Coop in Sweden have shut down 800 stores as they used an MSP on point of sale devices, who used Kaseya, so now they have REvil ransomware. Nightmare fuel. Should be a wake up call for governments, insurance, businesses etc. https://twitter.com/...
-
@clearing_fog
ClearingTheFog
on x
The attack is being publicly attributed to Russia-linked group REvil, the same group that previously attacked Brazilian meat packing company JBS. h/t @leesgirl9 https://twitter.com/...
-
@json_dirs
Jonny Saunders
on x
I'm not the one to call this, but given the state of security auditing in scientific software and the deployment scale and permissions required for some contemporary eg. app-based logging/survey/intervention tools, I wonder how long until one of ours is a vector. https://twitter.…
-
@janlemnitzer
Jan Lemnitzer
on x
First time I have seen an EU politician say on the record that the escalating ransomware impact is not only tolerated by Russia but serves its strategic goals of destabilizing the West. https://twitter.com/...
-
@bgroothuis
Bart Groothuis
on x
This is the ransomware nightmare any company or government can expect to happen. This is what we are working on in Brussels to prevent, in the new cyber security legislation #NIS2. But we need to be aware this is also a Russian foreign policy objective #safehaven @eu_eeas https:/…
-
@ciaranmartinoxf
Ciaran Martin
on x
Extraordinary: ransomware attack on American company disrupts 20% of Swedish food retail capacity, pharmacies, train ticket sales & they're not even direct customers https://twitter.com/...
-
@campuscodi
Catalin Cimpanu
on x
Supermarket chain Coop closes 800 stores across Sweden in the Kaseya ransomware fallout https://therecord.media/... https://twitter.com/...