On July 2nd, 2021 Kaseya released an advisory stating that they have been the target of a cyberattack. The attack targets the VSA platform which is a cloud-based IT management and remote monitoring solution with this attack only targeting only On-premise customers. End users are reporting that an automatic update in the VSA appliance dropped the REvil ransomware. Updates will be published as soon as they are available. PLEASE NOTE: Fusion IT does not utilize this service from Kaseya.
Recommendations:
Shutdown VSA appliances ASAP
First method of attack is disabling administrative access to VSA server
Block the following latest malicious samples (SHA256) from your environment: