It happened again - another disruptive ransomware cyber attack. On July 2, 2021 Kaseya, a Florida-based software provider that provides Remote Management Monitoring, warned of its software being abused to deploy ransomware on end-customers' systems.
The attack has been attributed to the REvil ransomware group, who have claimed to have encrypted over one million end-customer’s systems.
Kaseya has shut down its cloud-based Kaseya VSA product and has contacted their customers to do the same for on-premises Kaseya VSA deployments, while they patch the underlying vulnerabilities. Kaseya VSA is widely installed and so presents a large opportunity for attackers. Via netflow data recorded prior to the incident, Bitsight observed traffic from 7,500 endpoints connecting to Kaseya’s management endpoint; most of these were likely VSA clients.
After the attack, Bitsight data observed a steep decline in the count of vulnerable Kaseya servers exposed to the Internet, indicating that, encouragingly, most vendors responded quickly by taking instances offline. In the month preceding the incident, Bitsight observed approximately 1,900 Internet-facing Kaseya VSA instances. In contrast, a targeted scan on July 7 found fewer than 100 instances (which remained vulnerable, however).
Should we be surprised? Probably not.
Nearly 80 Ransomware attacks have occurred during each month of 2021 this year, according to Bitsight ransomware analysis. The REvil/Sodinokibi group is the market-leading “solution”, accounting for nearly 15% of attacks. Hackers are infiltrating victims with multiple tactics, including phishing and exploiting vulnerabilities, and then dropping the ransomware payload.
An alarming, but growing trend
The Kaseya attack underscores the software supply chain risks. Software vulnerability exploits lie at the heart of notable attacks, from the crippling 2017 NotPetya attack resulting from an exploited Ukranian accounting software vendor, to the recent SolarWinds, Hafnium, Accellion and now Kaseya incidents.
In April, 2021 NIST published recommendations on Defending Against Software Supply Chain Attacks. This followed the unusual step taken by the NSA in October 2020 to identify the top 25 software and hardware vulnerabilities being actively exploited by Chinese state-sponsored cyber actors.
Lone wolf cyber attackers are being eclipsed by threat actors operating at industrial scale. Some groups, including ReVil, are clearly financially motivated. Similar groups operate with similar business models seen in well known commercial brands - SLA’s, customer service, multiple fee-sharing agreements for ransom payments, etc.
The national security impact
From a national security perspective, state sponsored actors are drawing increasing attention. US President Biden added cyber security as part of the agenda in the bi-lateral conversations with Russia and also added it to the G7 agenda. Regardless of motivation, cyber attacks are both increasing in frequency and impact.
New CVE by year