Reveton is a Windows police-themed ransomware family that locks a victim’s screen and displays fraudulent law-enforcement notices accusing the user of crimes such as child pornography or piracy, then demands payment of a supposed fine to restore access. It is widely regarded as an early ransomware-as-a-service operation, emerging in 2011 and becoming prominent in 2012–2014, enabling lower-skilled affiliates to launch campaigns for a fee. Reveton is also referred to as Urausy in some reporting and is associated with a broader ecosystem of locker-style ransomware that preceded large-scale file-encrypting families.
Reveton primarily targeted Windows systems and commonly spread through drive-by compromise chains involving exploit kits, compromised websites, and malvertising. It was observed delivered via exploit kits including Blackhole, Angler, Cool, and related traffic-redirection infrastructure, and it was also pushed as a secondary payload through existing botnets. Distribution has been linked to campaigns using Citadel as a delivery component, as well as large malvertising operations that redirected victims through exploit infrastructure before installation.
Its core behavior is screen locking and extortion through spoofed police or federal-agency branding tailored to the victim’s geography. Variants impersonated agencies such as the FBI or local police and instructed victims to pay through prepaid voucher systems or similar payment channels. Some variants reportedly activated webcams to increase intimidation, and later versions were observed stealing stored passwords, indicating overlap between locker ransomware and credential-theft functionality. Reporting also notes that Reveton infections were frequently accompanied by additional malware, especially banking trojans or password-stealing components, making the visible lock screen only one part of the compromise.
Reveton is historically significant as one of the earliest mature ransomware affiliate businesses and as a bridge between scareware-style lockers and later industrialized ransomware ecosystems. Prosecutors and researchers have linked its development and operation to Belarusian cybercriminal Maksim Silnikau and associates, and the malware has also been connected to criminal groups involved in exploit kits and malvertising operations. Its campaigns affected consumers broadly, especially in North America and Europe, and demonstrated how exploit kits, traffic brokers, botnets, payment laundering, and affiliate programs could be combined into a scalable ransomware business model.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2015-0311 (Flash up to 16.0.0.287) integrating Exploit Kits Patched with Flash 16.0.0.296 ... first seen exploited by Angler EK ... soon after used in standalone mode in huge malvert campaign ... integrated today in RIG ... Fiesta ... Nuclear Pack ... Sweet Orange ... Neutrino ... Magnitude | ...in huge malvert campaign (pushing either Reveton, either Bedep...)
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
These sites ran a version of the Angler exploit kit, which exploited vulnerabilities in visitors' browsers to infect them with malware, and more specifically with Reveton, a ransomware strain that locked users' access to their PCs with messages perpetrating to have come from various law enforcement agencies, such as the FBI.
You might want to read "The Transition - "Reveton Team" or "Mr.J/Monster AV" from : Paunch's arrest...The end of an Era !
14 distinct techniques documented for this family, organized by ATT&CK tactic.
much of the Reveton activity traces back to a group that is controlling the operation using reverse proxies at dozens of servers scattered across data centers globally
24 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An early ransomware-as-a-service product that enabled low-skilled cybercriminals to conduct ransomware attacks for a fee and was used to extort victims.
Earlier ransomware family mentioned for comparison with CryptoLocker.
Referenced as earlier malware sharing technical similarities with DanaBot.
Locker-style ransomware and early RaaS that displayed fake law-enforcement warnings and demanded payment, including in bitcoin.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.