CASE DOSSIER sentenced

U.S. v. Yaroslav Vasinskyi (Kaseya VSA / REvil Ransomware)

Docket: 3:21-cr-00314 Court: U.S. District Court for the Northern District of Texas Opened: 2021-08-11 Sector: Managed Service Providers, Information Technology, Retail, Education

Key Facts

Status
SENTENCED
Legal disposition
Loss Amount
$70.0 million
Extortion demands totaled $70 million for universal decryptor; extensive operational stoppage across schools, grocery stores, and local governments.
Techniques
5
Verified mappings
Defendants
2
Named in charges
  • Legal Status: SENTENCED in U.S. District Court for the Northern District of Texas.
  • Primary Target Sector: Managed Service Providers, Information Technology, Retail, Education.
  • Documented Financial Loss: $70.0 million.
  • 5 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Ukrainian national and REvil ransomware affiliate responsible for deploying the ransomware attack that hijacked Kaseya VSA management software, instantly encrypting up to 1,500 downstream businesses on July 4th weekend.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Adversary initial penetration relied on exploitation of known vulnerabilities (CVE-2021-30116, CVE-2021-30117, CVE-2021-30118) combined with targeted spearphishing and stolen remote access credentials.

Operational & Financial Fallout

Extortion demands totaled $70 million for universal decryptor; extensive operational stoppage across schools, grocery stores, and local governments. Impacted Managed Service Providers, Information Technology, Retail, Education infrastructure and associated victim operations.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: SENTENCED
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Adversary initial penetration relied on exploitation of known vulnerabilities (CVE-2021-30116, CVE-2021-30117, CVE-2021-30118) combined with targeted spearphishing and stolen remote access credentials.

Adversary Kill Chain Flow

5 Documented Phases
1
Phase 1: Initial Access Initial Perimeter Infiltration
MITRE ATT&CK T1190 →

Vasinskyi exploited zero-day authentication bypass and SQL injection vulnerabilities in internet-facing Kaseya VSA servers.

Artifacts & Tooling: T1190 Exploit Public-Facing Application CVE-2021-30116 CVE-2021-30117
2
Phase 2: Execution Host Execution & Payload Staging
MITRE ATT&CK T1569.002 →

Vasinskyi used Kaseya VSA management agents to execute arbitrary PowerShell commands disguised as automated administrative service tasks.

Artifacts & Tooling: T1569.002 Service Execution CVE-2021-30116 CVE-2021-30117
3
Phase 3: Persistence Persistent Foothold Establishment
MITRE ATT&CK T1574.002 →

The attacker used DLL side-loading with an outdated signed Windows Defender executable (MsMpEng.exe) to execute the REvil ransomware payload.

Artifacts & Tooling: T1574.002 DLL Side-Loading CVE-2021-30116 CVE-2021-30117
4
Phase 4: Discovery Internal Subnet & Trust Reconnaissance
MITRE ATT&CK T1082 →

The REvil dropper checked host architecture and operating system language, aborting execution if Russian locale strings were detected.

Artifacts & Tooling: T1082 System Information Discovery CVE-2021-30116 CVE-2021-30117
5
Phase 5: Impact Operational Disruption or Extortion Detonation
MITRE ATT&CK T1486 →

Over 1,500 downstream client networks were locked with Salsa20 encryption in a synchronized automated broadcast on July 2, 2021.

Artifacts & Tooling: T1486 Data Encrypted for Impact CVE-2021-30116 CVE-2021-30117
Real-World Blast Radius & Operational Fallout

Extortion demands totaled $70 million for universal decryptor; extensive operational stoppage across schools, grocery stores, and local governments. Impacted Managed Service Providers, Information Technology, Retail, Education infrastructure and associated victim operations.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.
✓ Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.
✓ Maintain isolated, immutable backups of critical directory services and transaction databases.
✓ Deploy real-time endpoint detection and response (EDR) agents with automated containment policies.

Procedural & Incident Timeline

2021-10-08 arrest

Vasinskyi arrested by Polish authorities at the Polish-Ukrainian border.

2022-03-03 extradition

Extradited from Poland to the Northern District of Texas.

2022-11-01 plea

Pled guilty to conspiracy to commit computer fraud and damage, money laundering, and related charges.

2024-05-01 sentencing

Sentenced to 163 months (over 13 years) in federal prison and ordered to pay $16 million in restitution.

Named Defendants & Operatives

Defendant Nationality Status Prison Term Restitution Notes
Yevgeniy Polyanin Russian Federation fugitive Pending $6.1 million REvil affiliate indicted in N.D. Tex.; $6.1 million in ransom proceeds recovered by DOJ.
Yaroslav Vasinskyi Ukraine sentenced 156 mo None REvil ransomware affiliate who carried out the Kaseya VSA attack. Sentenced to over 13 years in federal prison.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1190 Exploit Public-Facing Application
Initial Access
"Vasinskyi exploited zero-day authentication bypass and SQL injection vulnerabilities in internet-facing Kaseya VSA servers." Indictment ¶ 14, Page 7 reviewed
T1574.002 DLL Side-Loading
Persistence
"The attacker used DLL side-loading with an outdated signed Windows Defender executable (MsMpEng.exe) to execute the REvil ransomware payload." CISA Advisory AA21-189A reviewed
T1486 Data Encrypted for Impact
Impact
"Over 1,500 downstream client networks were locked with Salsa20 encryption in a synchronized automated broadcast on July 2, 2021." Indictment ¶ 16, Page 8 reviewed
T1569.002 Service Execution
Execution
"Vasinskyi used Kaseya VSA management agents to execute arbitrary PowerShell commands disguised as automated administrative service tasks." Indictment ¶ 15, Page 8 reviewed
T1082 System Information Discovery
Discovery
"The REvil dropper checked host architecture and operating system language, aborting execution if Russian locale strings were detected." CISA Advisory AA21-189A reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, U.S. v. Yaroslav Vasinskyi (Kaseya VSA / REvil Ransomware), No. 3:21-cr-00314 (U.S. District Court for the Northern District of Texas 2021), https://cybercaselibrary.com/cases/us-v-vasinskyi-kaseya-revil/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/us-v-vasinskyi-kaseya-revil" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>