Reveton, also known as the Reveton Team or Reveton operators, is a financially motivated cybercriminal ransomware operation associated with the early development of ransomware-as-a-service. Its distribution ecosystem included affiliates and browser exploit kits, with the team using Cool Exploit Kit before adopting Angler Exploit Kit. Angler existed before the team's adoption and was used by other operators, so activity involving that exploit kit is not necessarily attributable to Reveton. U.K. law enforcement has linked Maksim Silnikau, known by aliases including J.P. Morgan, to Reveton's launch and described his network as helping pioneer exploit-kit and ransomware-as-a-service models. Reveton belongs to the earlier ransomware ecosystem surrounding these services; Silnikau's later alleged ransomware operations should not automatically be treated as Reveton activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Described as the first ransomware-as-a-service gang. U.K. police allegedly linked Silnikau to its launch; the article separately identifies Reveton as ransomware distributed through Angler.
Associated in the content with use of Angler EK after Paunch's arrest and previously using Cool EK as an affiliate/operator set.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.