REvil, also known as Sodinokibi, was a financially motivated ransomware operation associated with Russia. Its ransomware was first detected in April 2019, and the operation emerged as a successor to GandCrab. REvil operated a ransomware-as-a-service program: core operators supplied ransomware and supporting infrastructure, while affiliates compromised victim networks and deployed the malware in exchange for a share of ransom proceeds. Its targeting extended across industries and countries, including software suppliers, managed service providers, their downstream customers, and food-processing businesses. The operation avoided Russia-based organizations. REvil used file encryption and double extortion, combining ransom demands with threats to publish stolen information through a dedicated leak site. Affiliate intrusion methods varied. A prominent campaign on July 2, 2021 exploited multiple zero-day vulnerabilities in on-premises Kaseya Virtual System Administrator deployments, including CVE-2021-30116. Attackers bypassed authentication, uploaded a payload, and executed commands, then abused trusted remote-management functionality to distribute ransomware to downstream organizations. Kaseya reported approximately 60 directly affected customers and up to 1,500 downstream businesses. Unlike REvil's usual double-extortion model, data exfiltration was not observed in this campaign. Associated ransomware disabled its normal command-and-control communications and deleted shadow copies to impede recovery. REvil also attacked meat-processing company JBS, which paid an $11 million ransom in June 2021. The operation experienced interruptions during 2021 and had been inactive for several months before Russian authorities announced the arrest of 14 alleged members in January 2022. Authorities seized funds and equipment and stated that the group's infrastructure had been neutralized. Affiliates could move between ransomware programs; REvil's organizational identity should therefore be distinguished from individual affiliates and other operations that reused similar ransomware code.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
56 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
11 CVEs this actor has used in observed campaigns. 11 of them exploited in the wild.
DIVD CSIRT highlighted CVE-2021-30116 as a vulnerability being used in the ransomware attacks. The disclosure table describes it as a credentials leak and business logic vulnerability, patched in VSA 9.5.7a.
Patched vulnerabilities are as follows: CVE-2021-30120: Two Factor Authentication (2FA) bypass
Evidence points to the DDoS attacks coming from the massive Meris botnet. Meris sucks its power out of the thousands of internet-of-things (IoT) devices that have been hijacked thanks to a years-old vulnerability, tracked as CVE-2018-14847, in MicroTik routers.
Vulnerabilities Actively Exploited by Ransomware Threats: CVE-2019-11510 (Pulse Secure)
Vulnerabilities Actively Exploited by Ransomware Threats: CVE-2019-11539 (Pulse Secure)
6 more CVEs tied to this actor tracked in Mallory.
46 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a historical example of third-party compromise. REvil exploited Kaseya VSA and distributed ransomware to downstream businesses through managed service providers. The content does not attribute the EY breach to REvil.
A historical ransomware operation for which a decryptor was released for victims of versions active before its 2021 shutdown.
Defunct Russian-speaking RaaS operation known for affiliate-led attacks, including the Kaseya supply-chain compromise; its model and affiliates influenced later operations.
Упоминается как ransomware family/codebase, с которым сравнивали малварь Ransom Cartel; предполагается возможная связь через бывшего участника REvil.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.