{
  "id": "case-kaseya-revil",
  "slug": "us-v-vasinskyi-kaseya-revil",
  "title": "U.S. v. Yaroslav Vasinskyi (Kaseya VSA / REvil Ransomware)",
  "summary": "Ukrainian national and REvil ransomware affiliate responsible for deploying the ransomware attack that hijacked Kaseya VSA management software, instantly encrypting up to 1,500 downstream businesses on July 4th weekend.",
  "case_number": "3:21-cr-00314",
  "court": "U.S. District Court for the Northern District of Texas",
  "district": "N.D. Tex.",
  "country": "United States",
  "opened_at": "2021-08-11",
  "status": "sentenced",
  "victim_sector": "Managed Service Providers, Information Technology, Retail, Education",
  "victim_country": "United States, Sweden, New Zealand",
  "loss_amount_usd": 70000000,
  "loss_amount_note": "Extortion demands totaled $70 million for universal decryptor; extensive operational stoppage across schools, grocery stores, and local governments.",
  "first_seen_at": "2021-07-02T00:00:00Z",
  "last_updated_at": "2026-09-14T11:00:00Z",
  "actor_slug": "revil-sodinokibi",
  "defendant_slugs": [
    "yaroslav-vasinskyi",
    "yevgeniy-polyanin"
  ],
  "cves": [
    "CVE-2021-30116",
    "CVE-2021-30117",
    "CVE-2021-30118"
  ],
  "techniques": [
    {
      "technique_id": "T1190",
      "evidence_excerpt": "Vasinskyi exploited zero-day authentication bypass and SQL injection vulnerabilities in internet-facing Kaseya VSA servers.",
      "evidence_locator": "Indictment \u00b6 14, Page 7",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Vasinskyi",
      "source_url": "https://www.justice.gov/opa/pr/man-sentenced-role-revil-ransomware-attacks",
      "technique_name": "Exploit Public-Facing Application",
      "tactic": "Initial Access"
    },
    {
      "technique_id": "T1574.002",
      "evidence_excerpt": "The attacker used DLL side-loading with an outdated signed Windows Defender executable (MsMpEng.exe) to execute the REvil ransomware payload.",
      "evidence_locator": "CISA Advisory AA21-189A",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory AA21-189A",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-189a",
      "technique_name": "DLL Side-Loading",
      "tactic": "Persistence"
    },
    {
      "technique_id": "T1486",
      "evidence_excerpt": "Over 1,500 downstream client networks were locked with Salsa20 encryption in a synchronized automated broadcast on July 2, 2021.",
      "evidence_locator": "Indictment \u00b6 16, Page 8",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Vasinskyi",
      "source_url": "https://www.justice.gov/opa/pr/man-sentenced-role-revil-ransomware-attacks",
      "technique_name": "Data Encrypted for Impact",
      "tactic": "Impact"
    },
    {
      "technique_id": "T1569.002",
      "evidence_excerpt": "Vasinskyi used Kaseya VSA management agents to execute arbitrary PowerShell commands disguised as automated administrative service tasks.",
      "evidence_locator": "Indictment \u00b6 15, Page 8",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment",
      "source_url": "https://www.justice.gov/opa/pr/man-sentenced-role-revil-ransomware-attacks",
      "technique_name": "Service Execution",
      "tactic": "Execution"
    },
    {
      "technique_id": "T1082",
      "evidence_excerpt": "The REvil dropper checked host architecture and operating system language, aborting execution if Russian locale strings were detected.",
      "evidence_locator": "CISA Advisory AA21-189A",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory AA21-189A",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-189a",
      "technique_name": "System Information Discovery",
      "tactic": "Discovery"
    }
  ],
  "events": [
    {
      "event_type": "arrest",
      "event_date": "2021-10-08",
      "description": "Vasinskyi arrested by Polish authorities at the Polish-Ukrainian border."
    },
    {
      "event_type": "extradition",
      "event_date": "2022-03-03",
      "description": "Extradited from Poland to the Northern District of Texas."
    },
    {
      "event_type": "plea",
      "event_date": "2022-11-01",
      "description": "Pled guilty to conspiracy to commit computer fraud and damage, money laundering, and related charges."
    },
    {
      "event_type": "sentencing",
      "event_date": "2024-05-01",
      "description": "Sentenced to 163 months (over 13 years) in federal prison and ordered to pay $16 million in restitution."
    }
  ]
}