The REvil/Sodinokibi ransomware operation broadened its playbook by combining network-wide encryption with data theft, public leak threats, and dark-web auctions of stolen files. The gang threatened to publish or sell data taken from victims including GEDIA Automotive Group and other unnamed companies, sometimes releasing samples such as an Active Directory AdRecon report or promising daily disclosures of employee and financial records. REvil also launched an auction site to monetize stolen data from non-paying victims, with opening bids such as $50,000 in Monero, extending the pressure tactics already used in high-profile corporate extortion cases.
Intrusions tied to REvil also showed increasingly targeted post-compromise activity. Symantec observed attackers using Cobalt Strike, PowerShell, remote access tools, and account creation to move laterally, disable defenses, and deploy ransomware, while also scanning some victim networks for point-of-sale software that could enable payment-card theft or prioritize systems for encryption. Reported victims included a New York airport, a New Jersey synagogue, and organizations in services, food, and healthcare, while Microsoft said human-operated ransomware crews were exploiting exposed RDP, vulnerable internet-facing systems, and flaws such as CVE-2019-19781 and CVE-2019-11510 before spending weeks or months inside networks prior to encryption.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
18 events from the most recent confirmed update back to the earliest known activity.
By early June 2020, REvil launched an auction site to sell data stolen from victims to the highest bidder instead of only leaking it for free. ZDNET reported the first auction involved files from a Canadian agricultural company, with bidding starting at $50,000 in Monero.
Symantec said it had previously observed Sodinokibi attackers using AnyDesk in at least two attacks in April. The observation was cited as part of the group's use of legitimate remote administration tools.
Microsoft reported that many of the compromises enabling the April 2020 ransomware wave began earlier through vulnerable internet-facing devices, brute-forced RDP, misconfigured web servers, and exploitation of Citrix ADC CVE-2019-19781 and Pulse Secure VPN CVE-2019-11510. Operators commonly used credential theft, lateral movement, reconnaissance, and data exfiltration before deploying ransomware.
Microsoft observed dozens of human-operated ransomware deployments in the first two weeks of April 2020 after attackers had maintained access to victim networks for months. Affected sectors included aid organizations, medical billing, manufacturing, transport, government institutions, and educational software providers.
Sodinokibi/REvil threatened Kenneth Cole Productions with public release of allegedly stolen data unless a ransom was paid. The gang published download links to archives it said contained more than 70,000 internal documents and over 60,000 customer records.
Temple Har Shalom in Warren, New Jersey discovered a Sodinokibi ransomware attack on January 9, 2020 after staff had trouble connecting to the Internet. The attack encrypted server-based files, electronic data, and even the synagogue's mechanical backup.
The sources state that Nemty and BitPyLock adopted the tactic of stealing and leaking victim data during January 2020. This reflected the spread of double-extortion methods beyond Maze and Sodinokibi.
Albany International Airport said its administrative servers were hit by Sodinokibi during a cyberattack over Christmas. Administrative documents, archived data, and backup servers were encrypted, while operational, airline, TSA, and passenger data systems were not affected.
Sodinokibi announced in December 2019 that it would release stolen victim data if ransom demands were not met. This marked its adoption of leak-based extortion alongside file encryption.
Maze ransomware began the now-common tactic of leaking stolen victim data to pressure non-paying victims. The source cites late November 2019 as the start of this trend, including a 700 MB leak from Allied Universal.
The operators of GandCrab announced their retirement in June 2019. Reporting cited in the source says they were widely believed to have shifted to Sodinokibi afterward.
Sodinokibi ransomware first appeared in April 2019. It was widely believed to be linked to the operators behind GandCrab.
Symantec researchers identified a targeted Sodinokibi campaign in which attackers used Cobalt Strike, NetSupport, Pastebin, and Amazon CloudFront, and also scanned some victim networks for credit card or point-of-sale software. Eight organizations had Cobalt Strike infections and three victims in the services, food, and healthcare sectors were later infected with Sodinokibi.
The Sodinokibi/REvil operators said they had begun a forced transition from Bitcoin to Monero for ransom payments to make tracing by law enforcement more difficult. On their Tor payment site, Monero became the default and Bitcoin payments incurred a 10% premium.
Sodinokibi operators posted a new message on their leak site threatening to release more stolen data every day, sell Social Security numbers and dates of birth, and later expose allegedly damaging financial information from a victim that refused to pay. The move showed a more aggressive form of data-driven extortion.
FireEye reported targeted ransomware attacks using Ragnarok against unpatched Citrix ADC servers vulnerable to CVE-2019-19781. The attacks used post-exploitation scripts to scan for EternalBlue-vulnerable Windows systems and deploy the ransomware.
Sodinokibi operators threatened to publish and sell data allegedly stolen from GEDIA Automotive Group after claiming the company did not respond or pay. They said they had encrypted all computers on GEDIA's network and exfiltrated more than 50 GB of data, and published an AdRecon spreadsheet as proof.
After discovering the airport attack, the Albany County Airport Authority notified the FBI and New York State Cyber Command, hired ABS Solutions, severed ties with MSP Logical Net, and paid a ransom of under six figures because backups were unavailable. The insurer reimbursed part of the payment.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
10 references tracked. Mallory keeps watching after this page renders.
symantec-enterprise-blogs.security.com
Open sourcezdnet.com
Open sourcemicrosoft.com
Open sourcebleepingcomputer.com
Open sourcebleepingcomputer.com
Open sourcebleepingcomputer.com
Open sourcebleepingcomputer.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.