{
  "id": "case-kaseya-revil",
  "slug": "us-v-vasinskyi-kaseya-revil",
  "title": "U.S. v. Yaroslav Vasinskyi (Kaseya VSA / REvil Ransomware)",
  "summary": "Ukrainian national and REvil ransomware affiliate responsible for deploying the ransomware attack that hijacked Kaseya VSA management software, instantly encrypting up to 1,500 downstream businesses on July 4th weekend.",
  "case_number": "3:21-cr-00314",
  "court": "U.S. District Court for the Northern District of Texas",
  "district": "N.D. Tex.",
  "country": "United States",
  "opened_at": "2021-08-11",
  "status": "sentenced",
  "victim_sector": "Managed Service Providers, Information Technology, Retail, Education",
  "victim_country": "United States, Sweden, New Zealand",
  "loss_amount_usd": 70000000,
  "loss_amount_note": "Extortion demands totaled $70 million for universal decryptor; extensive operational stoppage across schools, grocery stores, and local governments.",
  "first_seen_at": "2021-07-02T00:00:00Z",
  "last_updated_at": "2026-09-14T11:00:00Z",
  "actor_slug": "revil-sodinokibi",
  "defendant_slugs": [
    "yaroslav-vasinskyi",
    "yevgeniy-polyanin"
  ],
  "cves": [
    "CVE-2021-30116",
    "CVE-2021-30117",
    "CVE-2021-30118"
  ],
  "techniques": [
    {
      "technique_id": "T1190",
      "evidence_excerpt": "Vasinskyi exploited zero-day authentication bypass and SQL injection vulnerabilities in internet-facing Kaseya VSA servers.",
      "evidence_locator": "Indictment \u00b6 14, Page 7",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Vasinskyi",
      "source_url": "https://www.justice.gov/opa/pr/man-sentenced-role-revil-ransomware-attacks",
      "technique_name": "Exploit Public-Facing Application",
      "tactic": "Initial Access"
    },
    {
      "technique_id": "T1574.002",
      "evidence_excerpt": "The attacker used DLL side-loading with an outdated signed Windows Defender executable (MsMpEng.exe) to execute the REvil ransomware payload.",
      "evidence_locator": "CISA Advisory AA21-189A",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory AA21-189A",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-189a",
      "technique_name": "DLL Side-Loading",
      "tactic": "Persistence"
    },
    {
      "technique_id": "T1486",
      "evidence_excerpt": "Over 1,500 downstream client networks were locked with Salsa20 encryption in a synchronized automated broadcast on July 2, 2021.",
      "evidence_locator": "Indictment \u00b6 16, Page 8",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Vasinskyi",
      "source_url": "https://www.justice.gov/opa/pr/man-sentenced-role-revil-ransomware-attacks",
      "technique_name": "Data Encrypted for Impact",
      "tactic": "Impact"
    },
    {
      "technique_id": "T1569.002",
      "evidence_excerpt": "Vasinskyi used Kaseya VSA management agents to execute arbitrary PowerShell commands disguised as automated administrative service tasks.",
      "evidence_locator": "Indictment \u00b6 15, Page 8",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment",
      "source_url": "https://www.justice.gov/opa/pr/man-sentenced-role-revil-ransomware-attacks",
      "technique_name": "Service Execution",
      "tactic": "Execution"
    },
    {
      "technique_id": "T1082",
      "evidence_excerpt": "The REvil dropper checked host architecture and operating system language, aborting execution if Russian locale strings were detected.",
      "evidence_locator": "CISA Advisory AA21-189A",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory AA21-189A",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-189a",
      "technique_name": "System Information Discovery",
      "tactic": "Discovery"
    }
  ],
  "events": [
    {
      "event_type": "arrest",
      "event_date": "2021-10-08",
      "description": "Vasinskyi arrested by Polish authorities at the Polish-Ukrainian border."
    },
    {
      "event_type": "extradition",
      "event_date": "2022-03-03",
      "description": "Extradited from Poland to the Northern District of Texas."
    },
    {
      "event_type": "plea",
      "event_date": "2022-11-01",
      "description": "Pled guilty to conspiracy to commit computer fraud and damage, money laundering, and related charges."
    },
    {
      "event_type": "sentencing",
      "event_date": "2024-05-01",
      "description": "Sentenced to 163 months (over 13 years) in federal prison and ordered to pay $16 million in restitution."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Adversary initial penetration relied on exploitation of known vulnerabilities (CVE-2021-30116, CVE-2021-30117, CVE-2021-30118) combined with targeted spearphishing and stolen remote access credentials.",
    "blast_radius": "Extortion demands totaled $70 million for universal decryptor; extensive operational stoppage across schools, grocery stores, and local governments. Impacted Managed Service Providers, Information Technology, Retail, Education infrastructure and associated victim operations.",
    "kill_chain": [
      {
        "phase": "Phase 1: Initial Access",
        "title": "Initial Perimeter Infiltration",
        "description": "Vasinskyi exploited zero-day authentication bypass and SQL injection vulnerabilities in internet-facing Kaseya VSA servers.",
        "technical_artifacts": [
          "T1190",
          "Exploit Public-Facing Application",
          "CVE-2021-30116",
          "CVE-2021-30117"
        ],
        "mitre_technique_id": "T1190"
      },
      {
        "phase": "Phase 2: Execution",
        "title": "Host Execution & Payload Staging",
        "description": "Vasinskyi used Kaseya VSA management agents to execute arbitrary PowerShell commands disguised as automated administrative service tasks.",
        "technical_artifacts": [
          "T1569.002",
          "Service Execution",
          "CVE-2021-30116",
          "CVE-2021-30117"
        ],
        "mitre_technique_id": "T1569.002"
      },
      {
        "phase": "Phase 3: Persistence",
        "title": "Persistent Foothold Establishment",
        "description": "The attacker used DLL side-loading with an outdated signed Windows Defender executable (MsMpEng.exe) to execute the REvil ransomware payload.",
        "technical_artifacts": [
          "T1574.002",
          "DLL Side-Loading",
          "CVE-2021-30116",
          "CVE-2021-30117"
        ],
        "mitre_technique_id": "T1574.002"
      },
      {
        "phase": "Phase 4: Discovery",
        "title": "Internal Subnet & Trust Reconnaissance",
        "description": "The REvil dropper checked host architecture and operating system language, aborting execution if Russian locale strings were detected.",
        "technical_artifacts": [
          "T1082",
          "System Information Discovery",
          "CVE-2021-30116",
          "CVE-2021-30117"
        ],
        "mitre_technique_id": "T1082"
      },
      {
        "phase": "Phase 5: Impact",
        "title": "Operational Disruption or Extortion Detonation",
        "description": "Over 1,500 downstream client networks were locked with Salsa20 encryption in a synchronized automated broadcast on July 2, 2021.",
        "technical_artifacts": [
          "T1486",
          "Data Encrypted for Impact",
          "CVE-2021-30116",
          "CVE-2021-30117"
        ],
        "mitre_technique_id": "T1486"
      }
    ],
    "defensive_takeaways": [
      "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
      "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
      "Maintain isolated, immutable backups of critical directory services and transaction databases.",
      "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
    ]
  }
}