Kaseya ransomware

I’m not sure whether any of our BigFix customers are also using Kaseya, but there is currently a widespread ransomware attack targeting MSPs/Kaseya customers. Early reports are indicating this is very widespread.

Kaseya is recommending customers shut down any on-premise VSA servers immediately.

I’m gauging whether there’s interest in providing IoC content for BigFix to check for compromise. Please direct message me if this would be useful.


There was, (a little), interest in building IoCs for this. I’m not entirely optimistic, as it looks to me like the damage may be done by the time these files show up on the system, but I still hope this helps someone.

If anyone has Kaseya agents, I could use some help validating the Analysis I’ve posted at https://bigfix.me/analysis/details/2998641

Any feedback & collaboration, at all, is much appreciated!

1 Like

Interesting! Thx for sharing!