UPDATED 23:09 EDT / JULY 07 2021

SECURITY

As fake updates target victims, Kaseya allegedly knew of exploited vulnerability in April

Users of software from Kaseya Ltd. are being targeted with fake updates following an attack by the REvil ransomware group, as it was revealed today that the company was allegedly informed of a vulnerability exploited in a ransomware attack by REvil earlier this month.

Detected by researchers at Malwarebytes Labs, the campaign targets potential victims with spam that pushes Cobalt Strike payloads disguised as Kaseya VSA security updates.

Cobalt Strike is penetration testing software with legitimate uses but can also be used by bad actors to attack a company. As noted in November, when the source code for software allegedly leaked, in the hands of hackers the software can be used to identify security issues that can be exploited.

The “malspam” campaign involves an email with a message asking victims to install an update from Microsoft Corp. to protect against ransomware. Attached to the email is a file labeled called SecurityUpdates.exe and the email also includes a link pretending to be a security update from Microsoft to patch Kaseya vulnerabilities. The attachment subsequently installs Cobalt Strike.

While victims are being targeted with fake security updates, the Dutch Institute for Vulnerability Disclosure has disclosed that it discovered one of the vulnerabilities exploited by REvil in early April and informed Kaseya at the time.

“After some deliberation, we decided that informing the vendor and awaiting the delivery of a patch was the right thing to do,” Frank Breedijk from DIVD explained in a blog post. “We hypothesized that, in the wrong hands, these vulnerabilities could lead to the compromise of large numbers of computers managed by Kaseya VSA.”

Breedijk added that Kaseya’s response to the disclosure had been “on point and timely, unlike other vendors,” and that the company released two patches to address the identified vulnerabilities.” Clearly, it didn’t address them all, however, with Breedijk adding that “we later learned that one of the two vulnerabilities used in the attack was one we previously disclosed to Kaseya VSA.”

Kaseya has yet to comment on the claim. If true and Kaseya failed to act, whether intentionally or by accident, it does raise the issue that the company could potentially face legal liability issues, potentially given the theft of data involved in the attack.

As of its latest updates today, Kaseya is still struggling with the aftermath of the REvil attack. The company has published a runbook of the changes that should be made to the on-premises environment so that customers can prepare for a patch release.

The news comes a day after the White House vowed to take action against Russia if the Kaseya REvil attack was proved to be linked to the country. REvil is a known Russian ransomware gang with a long history, although it’s not known to be directly linked to the Russian government.

Image: Malwarebytes/Kaseya

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.
About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.