REvil, also known as Sodinokibi, was a prominent Russian-speaking ransomware-as-a-service operation that emerged in 2019 and became widely regarded as a successor to GandCrab. The operation combined a core developer and infrastructure team with affiliates responsible for obtaining access to victim environments, conducting intrusions, and deploying ransomware. REvil was associated with high-profile enterprise and supply-chain incidents, including the 2021 Kaseya VSA attack, and was known for targeting large organizations across multiple countries and sectors. REvil’s tradecraft included initial access through compromised remote-access infrastructure and software vulnerabilities, followed by post-compromise activity such as PowerShell-based execution, downloading additional components, deleting volume shadow copies, and deploying ransomware across Windows environments. In the Kaseya intrusion chain, REvil used DLL sideloading and abuse of a legitimate security product to reduce detection. The group also developed Linux encryptors for VMware ESXi environments, reflecting a focus on virtualized enterprise infrastructure. The operation was a major driver of modern ransomware extortion practices. In addition to file encryption, REvil stole data and threatened public release, making it an early and influential practitioner of double extortion. It also expanded coercive pressure through leak-site publication, direct outreach to victims’ customers and business partners, threats to contact journalists or stock exchanges, voice-based harassment, and DDoS attacks offered to affiliates as an extortion service. Reporting also indicates at least some REvil affiliates adopted executive-focused data theft and targeted disclosure threats to pressure senior leadership. REvil maintained strong operational ties to the Russian-speaking cybercrime ecosystem. Multiple accounts place its activity in Russian-language underground forums, and its malware was documented excluding systems configured for Russian and other Commonwealth of Independent States languages, a common anti-targeting pattern among post-Soviet cybercriminal operations. The group has been linked to Russian-speaking affiliates and access brokers, and its operators were alleged to retain privileged cryptographic control over victim decryption and even to intervene in affiliate negotiations. Known aliases include Sodinokibi and variants referring to its affiliate ecosystem. REvil is frequently discussed alongside related or successor ecosystems such as GandCrab, DarkSide, BlackMatter, and ALPHV/BlackCat due to personnel overlap, shared tradecraft, or ecosystem continuity, but those are distinct operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
59 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
Evidence points to the DDoS attacks coming from the massive Meris botnet. Meris sucks its power out of the thousands of internet-of-things (IoT) devices that have been hijacked thanks to a years-old vulnerability, tracked as CVE-2018-14847, in MicroTik routers.
The threat actors behind the DearCry ransomware have already used the ProxyLogon vulnerability to deploy their ransomware...
The 2021 Kaseya VSA compromise by REvil used several zero-day vulnerabilities, including CVE-2021-30116 and CVE-2021-30120, which allowed them to bypass authentication requirements to access VSA servers en route to deploying ransomware in up to 1500 downstream client networks.
The 2021 Kaseya VSA compromise by REvil used several zero-day vulnerabilities, including CVE-2021-30116 and CVE-2021-30120, which allowed them to bypass authentication requirements to access VSA servers en route to deploying ransomware in up to 1500 downstream client networks.
45 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Упоминается как ransomware family/codebase, с которым сравнивали малварь Ransom Cartel; предполагается возможная связь через бывшего участника REvil.
Referenced as another ransomware group that went dark under law-enforcement pressure.
Conducted a large-scale ransomware supply-chain attack via Kaseya VSA, compromising MSPs and downstream customers; known for prolific ransomware operations, affiliate-based attacks, and extortion.
Mentioned as a comparative example of another ransomware operation running an affiliate program.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.