A Statement on the Kaseya Ransomware Attack
by DNSFilter on Jul 6, 2021, 12:00:00 AM
Just before US offices closed for the Fourth of July holiday, the MSP vendor Kaseya was hit by a huge ransomware attack. The organization behind the attack is REvil, a Russian-linked Ransomware-as-a-Service operation that first surfaced in May 2020. In 2021, they have been attached to a number of high-profile attacks. This breach is still ongoing, but we want to alert our customers to the actions that we have taken at DNSFilter to best secure our customers.
We want to reiterate that if you are a Kaseya customer to follow their advice:
“Our guidance continues to be that users follow Kaseya’s recommendation to shut down VSA servers immediately, to adopt CISA’s mitigation guidance, and to report if you have been affected to the IC3.”
Initial Domain Flagged
At 3:56 p.m. ET on July 2, DNSFilter categorized the first known URL as malware after it was first posted at roughly 3:19 p.m. ET: decoder[dot]re
Prior to our categorization of this domain, there was no traffic to this domain on our network.
Config file with over 1,000 domains disclosed
Early on July 3, a config file was released for the Kaseya attack that included a list of over 1,200 command and control domains. As of 3:58 a.m. ET on July 3, DNSFilter is categorizing all of these domains as malicious.
To ensure you’re protected from these domains sending DNS queries from your system, ensure you have the following DNS threat protection in place (at a minimum) on our network:
As more information is released or we have additional updates related to actions we are taking at DNSFilter to protect our customers, we will update this blog post.
Update on July 9, 2021: We have shared more information about the CNC domains used in the Kaseya ransomware attack.
How Black Hat Proved DNSFilter is on the Right Expansion Path
By Ken Carnesi, CEO & Co-Founder, DNSFilter
I've been going to Black Hat for years, and I can tell you plainly: This year was different.
Shadow AI and AI governance are top of mind now, an evolution from what we were hearing at RSA earlier this year. In an AI era, taking a DNS First approach to cybersecurity isn't optional, and we're built to solve exactly that problem.
I Went to Black Hat 2026 and Only Saw the Expo Floor. Here's What I Learned.
To see what our CEO Ken Carnesi thought of the week at Black Hat, check out his blog here.
Black Hat took over Mandalay Bay this week, and the official theme was impossible to miss: AI, everywhere, all at once. The keynotes covered cyber power in the age of AI, defending when offense is cheap, and vulnerability research in the agentic age. The vendor announcements were wall-to-wall AI agents, autonomous response, and identity security. TechTarg...
DNSFilter Earns 22 Badges in G2's Summer 2026 Reports
The G2 Summer 2026 reports are out, and DNSFilter earned 22 badges across the Grid® and index reports. Only a small fraction of the products on G2 earn a Leader badge in any given season, and this summer you named us a Leader across the overall Grid® Report, the Mid-Market Grid®, the Small-Business Grid®, and the EMEA Regional Grid®, along with Momentum Leader for ranking in the top 25% of our category.