REvil, also known as Sodinokibi or Sodin, is a ransomware family first observed in April 2019 and associated with the financially motivated GOLD SOUTHFIELD threat group. It operated through a ransomware-as-a-service model in which affiliates compromised organizations and deployed the ransomware in exchange for a share of ransom payments. The operation supported double extortion through a victim-data leak site alongside demands for payment to restore encrypted files.
REvil encrypts files on Windows systems, appends a randomly generated extension, and creates ransom notes directing victims to payment and negotiation services. Analyzed variants use Salsa20 for file encryption and AES to protect private-key material. The ransomware can inject itself into running processes and exploit the Windows Win32k vulnerability CVE-2018-8453 for privilege escalation. It employs obfuscation and anti-analysis techniques, including string encryption and API hashing. It also deletes volume shadow copies and disables automatic Windows recovery to impede restoration.
Distribution methods include malicious email attachments, macro-enabled Word documents, résumé-themed lures, compromised software downloads, and drive-by delivery through compromised websites. Affiliates have also deployed REvil after exploiting public-facing applications and VPN appliances, including Oracle WebLogic vulnerability CVE-2019-2725 and Pulse Connect Secure vulnerability CVE-2019-11510. Compromised managed service providers and remote-management infrastructure enabled deployment to downstream customers. In July 2021, a REvil affiliate exploited Kaseya VSA zero-day vulnerabilities, including CVE-2021-30116, in a large-scale attack against organizations served by managed service providers. Other prominent victims included Travelex and JBS, illustrating its impact on financial services and food production.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The initial compromise of Kaseya VSA servers appears to have been the result of the successful exploitation of an unpatched software vulnerability (CVE-2021-30116) which allowed attackers to obtain privileged access to vulnerable Kaseya VSA servers for the purposes of ransomware deployment.
Malicious activity exploiting the recently disclosed Oracle WebLogic critical deserialization vulnerability (CVE-2019-2725) is surging. Payloads include Sodinokibi, Muhstik, XMRig, and GandCrab.
These two families have been growing in popularity in 2019 and are notable for targeting enterprises and demanding unusually high ransoms.
Beaumont says this vulnerability was used to gain access to the vulnerable networks, followed by a similar pattern: obtaining domain administrator access, installing Virtual Network Computing (VNC) using PsExec for lateral movement, disabling endpoint security tools and installing the Sodinokibi ransomware, also known as Sodin or REvil.
These two families have been growing in popularity in 2019 and are notable for targeting enterprises and demanding unusually high ransoms.
Beaumont says this vulnerability was used to gain access to the vulnerable networks, followed by a similar pattern: obtaining domain administrator access, installing Virtual Network Computing (VNC) using PsExec for lateral movement, disabling endpoint security tools and installing the Sodinokibi ransomware, also known as Sodin or REvil.
In December 2019, Travelex was hit with a ransomware attack that leveraged a critical Citrix vulnerability (CVE-2019-19781). Following the attack, Sodinokibi (aka REvil) was observed targeting other vulnerable systems to spread ransomware.
Patched vulnerabilities are as follows: CVE-2021-30120: Two Factor Authentication (2FA) bypass | Kaseya released security patches for multiple vulnerabilities impacting the Kaseya VSA product, that was actively exploited in the recent REvil ransomware campaign.
Patched vulnerabilities are as follows: CVE-2021-30119: Cross-Site Scripting vulnerability | Kaseya released security patches for multiple vulnerabilities impacting the Kaseya VSA product, that was actively exploited in the recent REvil ransomware campaign.
Exploiting CVE-2018-13379, CVE-2019-11510, and valid accounts, which leads to the abuse of RDP and PsExec, and then the dropping of tools that disable antimalware, exfiltration tools, and, finally, REvil. | We examine three major ransomware families that employ these schemes: REvil (aka Sodinokibi), Clop, and Conti.
... as well as the BlueGate vulnerabilities affecting the Windows Remote Desktop Gateway (tracked as CVE-2020-0609 and CVE-2020-0610). | REvil (short for Ransomware Evil) is a revolutionary ransomware operation... Kaseya warned customers to immediately shut down their VSA server as REvil ransomware was spreading through its auto-update function.
... as well as the BlueGate vulnerabilities affecting the Windows Remote Desktop Gateway (tracked as CVE-2020-0609 and CVE-2020-0610). | REvil (short for Ransomware Evil) is a revolutionary ransomware operation... Kaseya warned customers to immediately shut down their VSA server as REvil ransomware was spreading through its auto-update function.
Computer giant Acer has been hit by a REvil ransomware attack where the threat actors are demanding the largest known ransom to date, $50,000,000.
21 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
REvil claims they have infected “more than a million systems” through this campaign and that they are willing to offer a universal decryptor tool for $70 million in Bitcoin.
FIN7 ... has been linked to other ransomware families such as Black Basta, DarkSide, REvil, and LockBit.
Travelex has confirmed that the ransomware is Sodinokibi which spreads using different methods, such as spearphishing emails, exploits and compromised websites.
The known threat actor “Unknown” on XSS associated with the Sodinokibi ransomware group announced in March 2020 that they were switching to Monero.
Kaseya released security patches for multiple vulnerabilities impacting the Kaseya VSA product, that was actively exploited in the recent REvil ransomware campaign.
Bassterlord, a suspected Russian-speaking threat actor who previously served as an affiliate for the LockBit ransomware gang, but also other rival RaaS operations, such as REvil, Avaddon, and RansomExx.
41 distinct techniques documented for this family, organized by ATT&CK tactic.
This delivery technique can also be classified in External Remote Services (ATT&CK T1133).
Attackers compromised WordPress sites and injected JavaScript over the content of the original site to spread Sodinokibi.
Attackers exploit vulnerabilities in enterprise applications to distribute it, such as the deserialization vulnerability CVE-2019-2725 in Oracle WebLogic Server.
VBA (Visual Basic for Applications) codes were split into modules and functions for the purpose of obfuscation.
258 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware used to evaluate real-time backup trigger strategies. Although the abstract lists Sodinokibi and REvil separately among its samples, they are names for the same family and are consolidated here. No family-specific behavior or results are provided.
Defunct Russian-speaking RaaS operation known for major extortion and supply-chain attacks, including the Kaseya incident. Its affiliates and code influenced successor operations.
Ransomware group/family discussed as the central case study, tied to criminal investigation and court proceedings in Russia. The content frames it as a double-extortion ransomware operation involving data encryption and threats to leak stolen data.
Known ransomware family whose code reportedly shared similarities with the Ransom Cartel encryptor.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.