Fake Kaseya VSA Security Update Drops Cobalt Strike
#1
Information 
Quote:A malware spam campaign is milking the Kaseya ransomware attacks against its Virtual System/Server Administrator (VSA) platform to spread a link pretending to be a Microsoft security update, along with an executable file that’s dropping Cobalt Strike, researchers warn.
 
On Tuesday night, Malwarebytes Threat Intelligence tweeted a screen capture of the boobytrapped email, which included an attachment named “SecurityUpdates.exe” and a message urging recipients to “install the update fro= microsoft to protect against ransomware as soon as possible. This is fi=ing a vulnerability in Kaseya.”

The attackers are looking to gain persistent remote access to the systems of targeted victims who fall for the ploy and run the malicious executable, or download and launch the fake Microsoft security update, on their devices.

Jerome Segura, a lead malware intelligence analyst at Malwarebytes, told Threatpost that so far, this is the first attack that’s been spotted piggybacking on the Kaseya attack.

While Malwarebytes hasn’t determined what threat actors are behind the Kaseya-themed malspam campaign, Segura said that the fake security update – the Cobalt Strike payload – is, interestingly enough, hosted on the same IP address used for another campaign pushing the Dridex banking trojan.

“In the past we’ve seen the same threat actor behind Dridex using Cobalt Strike,” Segura said via email.

Read more: Fake Kaseya VSA Security Update Drops Cobalt Strike | Threatpost
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Sysinternals Suite 3.26.2026
What's New (March ...harlan4096 — 11:40
AxCrypt 3.0.0.83
AxCrypt 3.0.0.83: ...harlan4096 — 11:39
Microsoft Edge 146.0.3856.84
Version 146.0.3856...harlan4096 — 11:37
PowerToys 0.98.1
Release v0.98.1 ...harlan4096 — 11:37
Opera 129.0.5823.28
Hello! A new Op...harlan4096 — 11:36

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
No upcoming birthdays.

[-]
Online Staff
There are no staff members currently online.

>