Hackers exploit Kaseya ransomware attack to launch spam campaign

Researchers at Malwarebytes say they found an email that poses as a patch for the Kaseya attack, but contains a malicious link and an attachment, purporting to have come from Microsoft.

July 14, 2021 02:13 pm | Updated 02:13 pm IST

Hackers exploit Kaseya ransomware attack to launch spam campaign.

Hackers exploit Kaseya ransomware attack to launch spam campaign.

Florida-based IT firm Kaseya was hit by a ransomware attack earlier this month affecting nearly 1,500 businesses in multiple countries . Hackers demanded $70 million in payment to restore the data in what was called the biggest ransomware attack on record.

(Subscribe to our Today's Cache newsletter for a quick snapshot of top 5 tech stories. Click here to subscribe for free.)

Now, researchers at Malwarebytes say they found an email that poses as a patch for the Kaseya attack, but contains a malicious link and an attachment, purporting to have come from Microsoft. It is urging users to install the update to fix the vulnerability. The email appears to be a reply that is part of an email thread to make users believe that the message is from a genuine source.

It reads, “Guys, please install the update from Microsoft to protect against ransomware as soon as possible. This is fixing a vulnerability in Kaseya.”

On further investigation, Malwarebytes team found that the location where the payload is hosted is the same IP address used in another malspam campaign that was pushing Dridex, a known information stealer.

While Kaseya has released patch for the flaws exploited by REvil, it advised that all companies should get patches straight from the vendor.

0 / 0
Sign in to unlock member-only benefits!
  • Access 10 free stories every month
  • Save stories to read later
  • Access to comment on every story
  • Sign-up/manage your newsletter subscriptions with a single click
  • Get notified by email for early access to discounts & offers on our products
Sign in

Comments

Comments have to be in English, and in full sentences. They cannot be abusive or personal. Please abide by our community guidelines for posting your comments.

We have migrated to a new commenting platform. If you are already a registered user of The Hindu and logged in, you may continue to engage with our articles. If you do not have an account please register and login to post comments. Users can access their older comments by logging into their accounts on Vuukle.