Kaseya Gets Hold of REvil Decryption Tool

Network service firm Kaseya has obtained a decryption tool for systems encrypted by the REvil ransomware after the supply-chain attack that caused ransomware troubles for many of Kaseya's clients.

The REvil group attack on Kaseya and downstream clients of the firm took place in the first days of June 2021. The original attack exploited three different zero-day vulnerabilities which have all since been patched. Customers were notified about the attack through multiple venues and Kaseya shut down its VSA servers as a precautionary measure, to limit the possible further spread of the REvil ransomware.

The attack was an instance of what infosec calls a "supply-chain attack", where one service provider is affected, and through them - further clients downstream who use the provider's services.

There is no hard information on whether or not Kaseya paid any ransom. What is known is that the original ransom demand was made to the tune of $70 million, which Threatpost reports was later toned down to $50 million.

What Kaseya did confirm in a notice issued on July 22 is that the company had obtained a decryption tool "from a third party" and multiple teams are actively working with multiple customers who got caught up in the ransomware attack.

The tool has already been confirmed to work and decrypt victims' files as expected.

Security researchers monitoring the unfolding events believe that there may have been a ransom payment effected, since the appearance of a universal decryption key that works for all victims of the attack is a little unusual. However, there is no evidence or official confirmation of the ransom really being paid and researchers believe that even if that is the case, the ransom sum had likely been negotiated further down from the $50 million mentioned above.

Other security researchers said that while the importance of the decryptor should not be downplayed or handwaved as something insignificant, there is still the problem of rebuilding all affected systems and networks and the matter of potentially exfiltrated information.

July 23, 2021
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.