Attackers leveraged trusted remote management software in two separate supply chain intrusions, including a ransomware case tied to Kaseya VSA and a credential-dumping operation delivered through a Desktop Central agent. In the Kaseya-linked incident, the intrusion chain used the Kaseya agent to create and decode malicious payloads, attempted to disable Microsoft Defender protections, and dropped ransomware-related components including agent.exe and MsMpEng.exe.
In the second intrusion, the attackers used the Desktop Central agent to gain footholds, established persistence with scheduled tasks, forwarded traffic with GO Simple Tunnel, and deployed setup0.exe alongside elevateutils.exe, which analysis identified as a Cobalt Strike Beacon Malleable C2 stager communicating with vmware[.]center. Investigators contained the activity through root-cause analysis, IOC hunting, and endpoint isolation, underscoring how centralized management platforms can become high-impact supply chain attack vectors if not closely monitored and hardened.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
One of the investigated incidents was tied to the Kaseya VSA ransomware incident. Trend Micro states this case was associated with the July 2 Kaseya event, in which attackers abused the Kaseya agent execution chain to deliver ransomware components.
After identifying affected hosts in the second incident, the MDR team added malicious IP addresses and hashes to a suspicious objects block list. They also recommended reviewing application logon logs for suspicious account use.
Root cause analysis in the second case found that setup0.exe created elevateutils.exe, with the earliest observed setup0.exe located on one affected host. Investigators assessed elevateutils.exe as a Cobalt Strike Beacon Malleable C2 stager communicating with vmware[.]center and concluded the malicious file had been deployed through a Desktop Central agent.
Threat hunting in the second incident identified suspicious WmiExec behavior and a scheduled task created with schtasks.exe to run powershell.exe C:\Windows\System.exe with network-forwarding arguments. Analysis linked System.exe to GO Simple Tunnel, indicating the attackers had established persistence and traffic-forwarding capability.
In a separate supply-chain case, investigators began with an alert about credential dumping in an Active Directory environment. Incident aggregation linked a server, an endpoint, and a user to the activity.
After the Kaseya-related attack, Kaseya told users to immediately shut down their Virtual System/Server Administrator servers until further notice. This was an official response aimed at containing the supply-chain compromise.
Trend Micro's MDR team alerted a customer after detecting ransomware activity in its environment during the Kaseya incident. The investigation found malicious use of AgentMon.exe, cmd.exe, certutil-based payload decoding, attempts to disable Windows Defender protections, and ransomware files including agent.exe and MsMpEng.exe; the team advised isolating Kaseya servers.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.