Researchers spot opportunistic phishing attacks in wake of Kaseya VSA ransomware
Phishing campaign claims to offer emergency patches to fix vulnerable software
Hackers have been discovered launching opportunistic phishing attacks against victims that pretend to be security updates for the Kaseya VSA product, vulnerable software recently exposed to a ransomware attack.
The phishing emails warn victims that they should “install the update from Microsoft to protect against ransomware as soon as possible. This is fixing a vulnerability in Kaseya", according to a blog post by Malwarebytes.
This appears to be a classic example of an opportunistic attack likely conducted by another hacking group off the back of a high-profile cyber attack, the researchers claim.
“With Kaseya being a big name in the MSP world and the company attempting to take their VSA SaaS platform off the ground, post-attack, it’s the perfect time and opportunity to also capitalize on organizations who are eagerly waiting for the hotfix that REvil exploited in the first place so they can get back to business as quickly as possible,” said the researchers.
The emails appear to be using SecurityUpdates.exe and ploader.exe as attachments, both of which use the Cobalt Strike payload.
Researchers also noted that the location where the payload is hosted appears to be the same IP address used in another malspam campaign that was pushing Dridex, a known information stealer. They added that hackers behind Dridex campaigns were also observed using Cobalt Strike.
RELATED RESOURCE
X-Force Threat Intelligence Index
Top security threats and recommendations for resilience
Cobalt Strike itself is legitimate software used as “adversary simulation software”, however, ransomware actors have abused such software to target organizations.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
Last month, researchers at Proofpoint said that the use of legitimate tools, such as Cobalt Strike, had increased 161% from 2019 to 2020 and remains a high-volume threat in 2021.
Researchers warned organizations affected by the Kaseya ransomware attack should only get patches straight from their vendor.
“Links and/or attachments sent over your way, even from a trusted colleague, should be suspect until you have confirmed with your vendor of the availability of a patch and where or how to get it,” they added.
“Opportunists will show no mercy in targeting cyber attack victims multiple times as long as they get something out of it.”
Researchers added that with the use of Cobalt Strike, hackers intend to also gain access to already-compromised systems, possibly for further reconnaissance or to conduct a local, follow-up attack.
Rene Millman is a freelance writer and broadcaster who covers cybersecurity, AI, IoT, and the cloud. He also works as a contributing analyst at GigaOm and has previously worked as an analyst for Gartner covering the infrastructure market. He has made numerous television appearances to give his views and expertise on technology trends and companies that affect and shape our lives. You can follow Rene Millman on Twitter.
-
At AMD Advancing AI, Helios was the star around which everything else revolvedOpinion The company's new rack-scale infrastructure is finally rolling off the production line, but there's a more petite offering to consider too
-
Gartner just revised its global IT spending projection for 2026 – here’s whyNews The analyst firm has made tweaks to previous predictions to reflect confidence in AI spending
-
Companies are still paying ransoms to cyber criminals despite official adviceNews A Proofpoint survey found evolving ransomware techniques and the use of AI is exacerbating the situation for victims
-
This one cyber crime group accounted for nearly a fifth of all ransomware attacks in JuneNews The Gentlemen, a ransomware a service operator, now accounts for 17% of published attacks
-
Working with the enemy: Ransomware negotiator-turned cyber criminal jailed after working with hackers to extort clientsNews Angelo Martino was supposed to be negotiating on behalf of victims, but was secretly working for ransomware operators
-
Hackers are posing as Interpol to target small businesses – here's what you need to knowNews Small businesses are warned to think twice before clicking on links
-
‘Every hour ransomware goes undetected drastically increases its potential blast radius’: Hackers are breaching networks and laying low for longer – and nearly half of firms don’t realize until data is stolenNews An ExtraHop survey found more intrusions are going undetected, leading to longer dwell times
-
Ransomware cartels are fragmenting into volatile splinter groups, warns Met Police cyber chiefNews Commoditized "cyber crime bazaars" and AI data mining are forcing law enforcement to rewrite its playbook
-
New ransomware threat group, The Gentlemen, has become one of the most active ransomware operators, accounting for 10% of all attacksNews NTT researchers warn that the RaaS group is leveraging SystemBC malware to establish covert tunnelling, evade detection, and support rapid lateral movement across enterprise environments
-
Instructure chose to a pay ransom following the Canvas cyber attack – research shows more than half of security leaders would follow suitAnalysis Opting to pay ransoms creates huge risks for enterprises – you’re relying on the word of criminals