Kaseya VSA 0-day - REvil Ransomware Supply Chain Attack

On July 2nd, Kaseya company has experienced an attack against the VSA (Virtual System/Server Administrator) product. Kaseya customers pointed out a ransomware outbreak in their environments. Further investigation revealed that REvil group exploited VSA zero-day vulnerabilities for authentication bypass and arbitrary command execution. This allowed the attacker to deploy ransomware on Kaseya customers' endpoints. This playbook should be trigger manually and includes the following tasks: * Collect related known indicators from several sources. * Indicators, PS commands, Registry changes and known HTTP requests hunting using PAN-OS, Cortex XDR and SIEM products. * Splunk advanced queries can be modified through the playbook inputs. * QRadar query is done using Reference Set and "QRadar Indicator Hunting V2" playbook * Search for internet facing Kaseya VSA servers using Xpanse. * Block indicators automatically or manually. * Provide advanced hunting and detection capabilities. * Mitigation using Kaseya On-Premises and SaaS patch. More information: [Kaseya Incident Overview & Technical Details](https://helpdesk.kaseya.com/hc/en-gb/articles/4403584098961) Note: This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve.

Pack
MajorBreachesInvestigationandResponse
Tasks
65

Inputs

Commands used