<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<p>Hello,</p>
<p>I hope everyone is doing well!</p>
<p><br>
</p>
<p>Below is the entry for today.</p>
<p><br>
</p>
<p>07/22/2021 - Diary entry #310:</p>
<p><br>
</p>
<blockquote style="margin-top:0;margin-bottom:0">
<div style="margin-top: 0px; margin-bottom: 0px;">
<p></p>
<p></p>
<p>Covered in our recent Daily Diaries (#307, #298 and #297), the supply-chain attack on Kaseya On-premises VSA appliances now gets an interesting outcome. Today, Kaseya announced they received from a trusted third party the universal decryptor for the ransomware
 attack and are now distributing it to their affected customers.</p>
<p><br>
</p>
<p>The attack was operated on July 2nd, through a zero-day vulnerability in the Kaseya VSA remote management application, enabling the threat to encrypt approximately sixty MSPs and around 1,500 businesses. After the attack, the group was offering their decryptor
 for $45k USD for each victim (or $70 million USD for a universal decryptor).</p>
<p><br>
</p>
<p>In our Daily Diary #307 we covered that the cybercrime group behind the attack, also known as Sodinokibi, is offline since July 13th. This disappearance is still a mystery, and the decryptor release raises even more questions. It's not clear if Kaseya paid
 a third party for the universal decryptor, and if this decryptor release is related to the websites shutdown.</p>
<p></p>
</div>
</blockquote>
<p><br>
</p>
<p>Kind Regards,</p>
<br>
</div>
<div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div id="Signature">
<div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<table style="font-size:medium; font-family:"Times New Roman"">
<tbody>
<tr>
<td style="width:180px" align="left">
<table width="120" align="left">
<tbody>
<tr>
<td colspan="3" align="center"><a href="https://www.appgate.com/" target="_blank" rel="noopener noreferrer" style="margin:0px"><img style="margin:0px" width="120" height="30" src="https://d3aafpijpsak2t.cloudfront.net/images/Signature/logo@2x.png"></a></td>
</tr>
<tr>
<td colspan="3" align="center"> </td>
</tr>
<tr>
<td width="37%" align="center"><a href="https://www.linkedin.com/company/appgate-security/" target="_blank" rel="noopener noreferrer" style="margin:0px"><img style="margin:0px" width="18" height="18" src="https://d3aafpijpsak2t.cloudfront.net/images/Signature/likedin@2x.png"></a></td>
<td width="28%"><a href="https://twitter.com/AppgateSecurity" target="_blank" rel="noopener noreferrer" style="margin:0px"><img style="margin:0px" width="20" height="18" src="https://d3aafpijpsak2t.cloudfront.net/images/Signature/twitter@2x.png"></a></td>
<td width="35%"><a href="https://www.youtube.com/channel/UC-8GvxcZbm-R3EJNl8jYjiQ" target="_blank" rel="noopener noreferrer" style="margin:0px"><img style="margin:0px" width="26" height="18" src="https://d3aafpijpsak2t.cloudfront.net/images/Signature/youtube@2x.png"></a></td>
</tr>
</tbody>
</table>
<p style="margin-top:0px; margin-bottom:0px"> </p>
</td>
<td colspan="2" rowspan="2" style="width:350px">
<p style="color:rgb(12,12,12); font-size:13px; font-family:Arial,Helvetica,sans-serif; margin-top:0px; margin-bottom:0px">
<strong>Felipe Tarijon de Almeida</strong><br>
Malware Analyst<br>
<strong>Appgate</strong></p>
<p style="color:rgb(12,12,12); font-size:13px; font-family:Arial,Helvetica,sans-serif; margin-top:0px; margin-bottom:0px">
E:<span style="margin:0px"> </span><font color="#228EBE"><a href="mailto:felipe.duarte@appgate.com" target="_blank" rel="noopener noreferrer" title="mailto:felipe.duarte@appgate.com" style="margin:0px">felipe.tarijon@appgate.com</a></font><br>
O:<span> </span><span style="margin:0px; background-color:white">+55 11 97467 9549</span></p>
</td>
</tr>
</tbody>
</table>
<br>
</div>
</div>
</div>
</div>
</body>
</html>