/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

In a post on the REvil dark web blog, the gang takes credit for the Kaseya attack, claims it infected 1M+ systems, and demands $70M in bitcoin for the decryptor

The REvil ransomware gang is asking for a $70 million ransom payment to publish a universal decryptor that can unlock …

The Record Catalin Cimpanu

Context & Ripple Effects

The immediate backdrop was REvil's use of a malicious Kaseya software update against managed service providers and their customers. Its demand for a single decryptor turns that distribution path into leverage over a far wider set of affected organizations.

The episode's arc later shifted from the ransom demand to Kaseya's announcement that it had obtained a universal decryptor and begun helping customers recover. That makes the initial claim significant as a test of how quickly a software supplier can restore customers after a compromised update.

First-order effects

  • REvil puts Kaseya and the companies reached through its management software under pressure to regain access to affected systems, while seeking $70 million for one decryptor.
  • Kaseya becomes the recovery intermediary for affected customers because the proposed decryptor is designed to work across the incident rather than for a single victim.

Second-order effects

  • Managed service providers hit through Kaseya must coordinate recovery with both Kaseya and their own customers, concentrating operational pressure on the supplier's response.
  • Kaseya's later access to a universal decryptor shifts the immediate priority from negotiating individual recoveries to distributing a common recovery tool to customers.

Third-order effects

  • The incident illustrates how compromise of an IT management update can concentrate ransomware exposure across service providers and their customer bases, making supplier security and recovery capacity a shared dependency.
  • If attackers continue targeting centrally managed software, ransomware disruption will increasingly be organized around software distribution channels rather than isolated victim networks.

The trend: Ransomware groups are targeting centralized software-management channels to amplify both the scale of disruption and the leverage of a single extortion demand.

Discussion

  • @vxunderground Vx-Underground on x
    REvil has named its price. $70,000,000 USD in Bitcoin. Attached image is directly from REvils website: https://twitter.com/...
  • @pwnallthethings @pwnallthethings on x
    So if you want a spicy take, although the direct impact of this is relatively small /so far/, its strategic impact dwarfs everything else in cybersecurity this year by a margin including Exchange hack, Colonial pipeline hack, and maybe even SolarWinds. https://twitter.com/...
  • @campuscodi Catalin Cimpanu on x
    Why would REvil pull such a brash attack right after the Colonial and JBS attacks and the political mess/fallouts from those incidents? -Wouldn't this attack confirm that REvil had some sort of approval from a RU agency before doing something this destructive?
  • @campuscodi Catalin Cimpanu on x
    Was the timing of the attack on the July 4 weekend a decision made for political reasons or was it REvil's typical modus operandi to hit over big western holiday breaks (which they have done many times before)? -Why are they asking a payment for an universal decrypter?
  • @campuscodi Catalin Cimpanu on x
    Did they realize that negotiating ransoms with thousands of companies at the same time is not worth the effort? -Will that universal decrytper even work, or are companies going to encounter bugs with large files? -Will Kaseya even consider paying?
  • @campuscodi Catalin Cimpanu on x
    Some questions in regards to the Kaseya incident: -How did REvil learn of the VSA exploit? -Did they have access to Kaseya's vulnerability disclosure systems? -Where they provided the exploit by a 3rd-party? -Was that 3rd-party an RU intelligence agency or exploit broker?
  • @campuscodi Catalin Cimpanu on x
    Apparently, this would be one gigantic discount. So nice of REvil... 😅 https://twitter.com/...
  • @campuscodi Catalin Cimpanu on x
    Scoop/breaking: The REvil ransomware gang is asking for $70 million to publish a universal decryptor that can unlock all computers locked during the Kaseya incident https://therecord.media/... https://twitter.com/...
  • @campuscodi Catalin Cimpanu on x
    In a message posted on their dark web blog, the REvil gang officially took credit for the attack for the first time and claimed they locked more than one million systems during the Kaseya incident.
  • @bdsams Brad Sams on x
    The legitimacy of BTC would be vastly improved if it wasn't universally associated with ransom payments. https://twitter.com/...
  • @ncweaver Nicholas Weaver on x
    This is possibly even MORE disturbing than a supply chain attack, because it brings up the possibility at least of a “lab leak”, the ransomware gang learning of the exploit itself OR at least plans to patch it. Leaks like this don't affect a single vendor. https://twitter.com/...
  • @serghei @serghei on x
    “Although the scale of this incident may make it so that we are unable to respond to each victim individually, all information we receive will be useful in countering this threat.” 👀 https://twitter.com/...
  • @0xdude Victor Gevers on x
    During the last 48 hours, the number of Kaseya VSA instances that are reachable from the internet has dropped from over 2.200 to less than 140 in our last scan today. https://csirt.divd.nl/...
  • @esetresearch @esetresearch on x
    #ESETresearch responded to ransomware deployed as supply-chain attack against #Kaseya VSA users attributed to #REvil beginning Friday afternoon EDT (US)/evening CEST (Europe). Detection was added for Win32/Filecoder.Sodinokibi.N on Friday shortly after.https://www.welivesecurity.…
  • @uscert_gov Us-Cert on x
    .@CISAgov and @FBI strongly recommend MSPs and #MSP customers affected by the Kaseya VSA supply-chain #ransomware attack take immediate action. See https://us-cert.cisa.gov/... for recommendations. #Cybersecurity #InfoSec #Ransomware
  • @kaseyacorp @kaseyacorp on x
    Updates Regarding VSA Security Incident July 4, 2021 - 10:00 AM EDT Next Update will be published July 4, 2021, in the early afternoon EDT https://www.kaseya.com/...
  • @_johnhammond John Hammond on x
    If you haven't seen it, Kaseya has now shared their own detection tool. From their report, “The new Compromise Detection Tool was rolled out last night to almost 900 customers who requested the tool.” https://helpdesk.kaseya.com/ ...
  • @raj_samani Raj Samani on x
    Some small respite for victims of the Kaseya attack - “REvil representatives have told victims that they only encrypted networks, and nothing more. This means that REvil likely did not steal any of the victims' data” https://www.bleepingcomputer.com/ ... #ransomware #malware #cyb…
  • @bad_packets Bad Packets Llc on x
    @FBI The vendor says, “Only a very small percentage of our customers were affected - currently estimated at fewer than 40 worldwide.” The FBI says, “Although the scale of this incident may make it so that we are unable to respond to each victim individually.” 🤔
  • @fbi @fbi on x
    #FBI Statement on Kaseya Ransomware Attack @CISAgov https://www.fbi.gov/... https://twitter.com/...
  • @randahabib Randa Habib on x
    President Joe Biden said he has directed U.S. intelligence agencies to investigate who was behind a sophisticated ransomware attack that hit hundreds of American businesses and led to suspicions of Russian gang involvement. https://www.reuters.com/...
  • @gossithedog Kevin Beaumont on x
    Coop in Sweden have shut down 800 stores as they used an MSP on point of sale devices, who used Kaseya, so now they have REvil ransomware. Nightmare fuel. Should be a wake up call for governments, insurance, businesses etc. https://twitter.com/...
  • @clearing_fog ClearingTheFog on x
    The attack is being publicly attributed to Russia-linked group REvil, the same group that previously attacked Brazilian meat packing company JBS. h/t @leesgirl9 https://twitter.com/...
  • @json_dirs Jonny Saunders on x
    I'm not the one to call this, but given the state of security auditing in scientific software and the deployment scale and permissions required for some contemporary eg. app-based logging/survey/intervention tools, I wonder how long until one of ours is a vector. https://twitter.…
  • @janlemnitzer Jan Lemnitzer on x
    First time I have seen an EU politician say on the record that the escalating ransomware impact is not only tolerated by Russia but serves its strategic goals of destabilizing the West. https://twitter.com/...
  • @bgroothuis Bart Groothuis on x
    This is the ransomware nightmare any company or government can expect to happen. This is what we are working on in Brussels to prevent, in the new cyber security legislation #NIS2. But we need to be aware this is also a Russian foreign policy objective #safehaven @eu_eeas https:/…
  • @ciaranmartinoxf Ciaran Martin on x
    Extraordinary: ransomware attack on American company disrupts 20% of Swedish food retail capacity, pharmacies, train ticket sales & they're not even direct customers https://twitter.com/...
  • @campuscodi Catalin Cimpanu on x
    Supermarket chain Coop closes 800 stores across Sweden in the Kaseya ransomware fallout https://therecord.media/... https://twitter.com/...