REvil ransomware attack under analysis

SophosNews

Share post

The successful ransomware attack on Kaseya's Virtual Systems Administrator (VSA) software affects a large number of companies that use the software. A comment from Mark Loman, Director of Engineering at Sophos, on the current REvil ransomware attack on Kaseya.

“Since the latest attack with the ransomware REvil became known, Sophos has carried out numerous investigations and classified the attack under the heading 'Supply Chain Distribution'. The criminals use Managed Service Providers (MSP) as a 'sales platform' to hit as many companies as possible, regardless of size or industry.

Ransomware uses MSPs as a distribution platform

We see a recurring pattern here as attackers are constantly adapting their methods with the maxim to achieve the greatest possible impact, be it financially or stealing credentials and other proprietary information that they could later use. In other large-scale attacks we've seen in the past, such as WannaCry, the ransomware itself was the distributor. In the current case, it became clear shortly after the attack that a REvil Ransomware-as-a-Service (RaaS) partner was using a zero-day exploit to distribute the ransomware via Kaseya's Virtual Systems Administrator (VSA) software . Typically, this software provides a highly trusted communication channel that gives MSPs unlimited privileged access to help many businesses with their IT environments. Exactly this platform has now been converted into a distributor for the ransomware. "

Ransom in the millions

“Some successful ransomware groups have looted millions of dollars in ransom money, which can potentially earn them very valuable zero-day exploits. So far, certain exploits have usually only been feasible at the nation-state level, which usually use these tools specifically for a specific, isolated attack. In the hands of cyber criminals, such a 'premium exploit' for a vulnerability in a global platform can hit many companies at the same time and have an impact on our daily lives. "

Based on Sophos Threat Intelligence, REvil has been particularly active in recent weeks, including the JBS attack, and is currently the dominant ransomware gang involved in Sophos' defensive managed threat response cases.

More at Sophos.com

 


About Sophos

More than 100 million users in 150 countries trust Sophos. We offer the best protection against complex IT threats and data loss. Our comprehensive security solutions are easy to deploy, use and manage. They offer the lowest total cost of ownership in the industry. Sophos offers award-winning encryption solutions, security solutions for endpoints, networks, mobile devices, email and the web. In addition, there is support from SophosLabs, our worldwide network of our own analysis centers. The Sophos headquarters are in Boston, USA and Oxford, UK.


 

Matching articles on the topic

Report: 40 percent more phishing worldwide

The current spam and phishing report from Kaspersky for 2023 speaks for itself: users in Germany are after ➡ Read more

BSI sets minimum standards for web browsers

The BSI has revised the minimum standard for web browsers for administration and published version 3.0. You can remember that ➡ Read more

Stealth malware targets European companies

Hackers are attacking many companies across Europe with stealth malware. ESET researchers have reported a dramatic increase in so-called AceCryptor attacks via ➡ Read more

IT security: Basis for LockBit 4.0 defused

Trend Micro, working with the UK's National Crime Agency (NCA), analyzed the unpublished version that was in development ➡ Read more

MDR and XDR via Google Workspace

Whether in a cafe, airport terminal or home office – employees work in many places. However, this development also brings challenges ➡ Read more

Test: Security software for endpoints and individual PCs

The latest test results from the AV-TEST laboratory show very good performance of 16 established protection solutions for Windows ➡ Read more

AI on Enterprise Storage fights ransomware in real time

NetApp is one of the first to integrate artificial intelligence (AI) and machine learning (ML) directly into primary storage to combat ransomware ➡ Read more

FBI: Internet Crime Report counts $12,5 billion in damage 

The FBI's Internet Crime Complaint Center (IC3) has released its 2023 Internet Crime Report, which includes information from over 880.000 ➡ Read more