Reveton is a Windows ransomware family best known for police-themed screen locking and extortion. It blocks access to the infected computer and displays fraudulent notices impersonating law-enforcement agencies, including the FBI and national police services. These notices accuse victims of accessing illegal material or violating copyright and demand payment of a purported fine to restore access. Notices are tailored to the victim’s country, and payments have been requested through prepaid voucher services such as MoneyPak, Ukash, and Paysafecard. Payment does not reliably restore access. Its characteristic extortion mechanism is screen locking rather than file encryption.
Reveton has been distributed through drive-by downloads from malicious or compromised websites and through malvertising, including advertisements placed on adult websites. Distribution infrastructure has used the Blackhole, Cool, Angler, and Styx exploit kits to exploit vulnerable browsers and plugins. Reveton has also been delivered through existing malware infections, including Citadel and Smokebot. Some variants activate the victim’s webcam and display the captured image on the lock screen to reinforce the intimidation. Later variants also steal passwords stored on the infected computer.
Reveton became prominent in consumer-targeted campaigns across Europe and the United States in 2012 and was offered through an early ransomware-as-a-service model that enabled affiliates to conduct attacks for a fee. Convicted distributor Zain Qaiser used malicious advertisements and the Angler exploit kit to deliver Reveton and collected ransom proceeds through a money-laundering network. Its campaigns often installed additional malware alongside the visible locker, so regaining desktop access did not necessarily eliminate the underlying compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
On September 13, 2016 Microsoft released a security bulletin fixing the CVE-2016-3351 vulnerability, which included a patch for Internet Explorer and Edge browsers. Researchers found exploitation dating back to January 2014, including a malvertising chain leading to Angler EK and dropping Reveton.
CVE-2015-0311 (Flash up to 16.0.0.287) integrating Exploit Kits Patched with Flash 16.0.0.296 ... first seen exploited by Angler EK ... soon after used in standalone mode in huge malvert campaign ... integrated today in RIG ... Fiesta ... Nuclear Pack ... Sweet Orange ... Neutrino ... Magnitude | ...in huge malvert campaign (pushing either Reveton, either Bedep...)
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Figure 5: CVE-2016-3351 used as early as January 2014 in malvertising chain to Angler EK dropping Reveton
These sites ran a version of the Angler exploit kit, which exploited vulnerabilities in visitors' browsers to infect them with malware, and more specifically with Reveton, a ransomware strain that locked users' access to their PCs with messages perpetrating to have come from various law enforcement agencies, such as the FBI.
You might want to read "The Transition - "Reveton Team" or "Mr.J/Monster AV" from : Paunch's arrest...The end of an Era !
14 distinct techniques documented for this family, organized by ATT&CK tactic.
much of the Reveton activity traces back to a group that is controlling the operation using reverse proxies at dozens of servers scattered across data centers globally
28 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An early ransomware-as-a-service product that enabled low-skilled cybercriminals to conduct ransomware attacks for a fee and was used to extort victims.
Earlier ransomware family mentioned for comparison with CryptoLocker.
Referenced as earlier malware sharing technical similarities with DanaBot.
Ransomware distributed using Angler. The article describes Reveton as the first ransomware-as-a-service gang and reports a UK police allegation that Silnikau was involved in its launch.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.