An update on the Kaseya ransomware attack CNC domains
by Peter Lowe on Jul 9, 2021 12:00:00 AM
Command and Control Domains
The attack by REvil used several domains, called "Command and Control" domains (also referred to as "C2 domains" or "CNC domains"), which are used after a system has been attacked. The purpose in this case is to notify REvil that the systems had been encrypted.
The configuration file of the ransomware was published by Fabian Wosar on GitHub. From that file, we extracted the list of domains. These domains are not all actually compromised systems—it's likely that only a few are, and the rest are either decoys or have been cleaned up.
Out of an abundance of caution, DNSFilter has marked all of these domains as malicious. We did so on July 3rd, when the domains were first made available. We are doing our best to verify entries and investigate specific aspects of the CNC servers, in order to eliminate false positives from the list.
This was published on GitHub as a service to others—it's an unsorted list in the config file, so making this more easily available could help others who are investigating.
Important notes
The domains shouldn't be taken as a list of compromised systems. It is simply an extract from the config file of domains marked there as "command and control".
If there are any entries that can be verified as clean, please contact us or submit a pull request on the GitHub repository.
Further information
For more information on REvil and the Kaseya ransomware attack, please check out these thorough overviews:
The Visibility Gap: Why Seeing is the Only Antidote to Shadow IT
Every CISO and security engineer eventually has to face: they no longer own their network.
In the era of the decentralized office, the traditional perimeter hasn't just been breached; it has evaporated. It vanished the moment an employee signed up for an AI tool using their corporate email. It vanished when a department stood up a SaaS suite on a personal credit card. It vanishes every time an employee decides that convenience is more important...
Maximum Protection, Minimum Friction: Announcing DNS PreCheck
In the modern era of the hybrid workforce, the traditional corporate perimeter is a thing of the past. Employees have the freedom to connect from home, airport lounges, international hotels, and everywhere in between. While this is a win for productivity, it can be a headache for IT teams who have zero control over the network configuration.
Securing Airline Public Wi-Fi: Stop Threats With Protective DNS
Public Wi-Fi has become a standard part of modern air travel. Whether streaming content or coordinating travel plans in real time, passengers expect to be connected at the gate, onboard the plane, and throughout their journey.
