Discovery Enum
- AdFind
- Bloodhound
REvil, also known as Sodinokibi or Sodin, is a Windows ransomware family and ransomware-as-a-service operation that was among the most prolific extortion threats of the early 2020s.
Profile source: Mallory opens in a new tabREvil
REvil, also known as Sodinokibi or Sodin, is a Windows ransomware family and ransomware-as-a-service operation that was among the most prolific extortion threats of the early 2020s. It is associated with large-scale double-extortion campaigns in which victim data is stolen prior to encryption and payment is demanded for both decryption and non-disclosure. Reported victimology spans private companies, government offices, schools, hospitals, law enforcement entities, and managed service provider downstream customers.
REvil is known for enterprise-focused intrusion activity and for excluding certain systems based on language settings, terminating execution when the host language matches entries in its internal exclusion list. The malware can query and modify the Windows Registry, including storing encryption parameters and runtime configuration artifacts there. It appends randomized encrypted-file extensions, gathers system information, and uses robust asymmetric and symmetric cryptographic routines during file encryption.
Operationally, REvil has been linked to high-impact supply-chain abuse, most notably the July 2021 compromise of on-premises Kaseya VSA servers, where attackers exploited a code-injection vulnerability to distribute the ransomware through managed service provider infrastructure to downstream endpoints. In that intrusion chain, the payload was executed via DLL sideloading after security controls were disabled. REvil has also been referenced as a technical predecessor or code relative of later ransomware families, with multiple researchers noting substantial overlaps between REvil and Ransom Cartel, including encryption workflow, configuration structure, and session-secret generation, while also observing that later derivatives appeared to lack REvil’s full obfuscation capability.
The operation has been widely tracked as a major Russian-speaking cybercriminal ransomware ecosystem. Public reporting has tied alleged members and administrators to attacks conducted from 2019 through 2021, with more than 1,000 victims attributed in charging materials. REvil’s prominence, technical maturity, and role in major extortion and supply-chain incidents made it a defining ransomware threat of its era.
Reported operators
REvil aka Sodinokibi, Sodin is a ransomware family operated as a ransomware-as-a-service (RaaS). Deployments of REvil first were observed in April 2019, where attackers leveraged a vulnerability in Oracle WebLogic servers tracked as CVE-2019-2725.
In 2023, FIN7 expanded its operations to include the deployment of ransomware through affiliations with RaaS groups such as REvil and Maze, while also managing its own RaaS programs, including the now-retired Darkside and BlackMatter.
In 2020 ELBRUS transitioned from using PoS malware to deploying ransomware as part of a financially motivated extortion scheme, specifically deploying the MAZE and Revil RaaS families.
One group known for pivoting is Evil Corp., the gang behind Revil. Revil’s tactics align with why a threat group would target an insurance provider.
In 2020 ELBRUS transitioned from using PoS malware to deploying ransomware as part of a financially motivated extortion scheme, specifically deploying the MAZE and Revil RaaS families.
UNC2628 is thought to partner with other RaaS services including REvil and Netwalker.
Between June 2020 and March 2021, Lockean attacked at least seven more companies with various ransomware families: Maze, Egregor, ProLock, REvil.
Between June 2020 and March 2021, Lockean attacked at least seven more companies with various ransomware families: Maze, Egregor, ProLock, REvil.
GOLD SOUTHFIELD has used the cloud-based remote management and monitoring tool "ConnectWise Control" to deploy REvil.
"REvil, also known as Sodinokibi, emerged in 2019 and is widely believed to have evolved out of the GandCrab ransomware group."
Exploited software
MITRE ATT&CK
Reporting
Armenian authorities detained Russian tourist Aleksandr Yuryevich Ermakov in Yerevan on June 28 under a U.S. extradition request tied to alleged REvil ransomware activity, but his lawyers say he is not the wanted cybercriminal. The dispute centers on whether U.S. prosecutors and an Interpol notice were actually seeking Aleksandr Gennadievich Ermakov, a different Russian man sanctioned by the United States, United Kingdom, and Australia for alleged links to REvil and the 2022 Medibank breach. Reporting indicates the extradition paperwork may have omitted key identifying details, including a patronymic, creating the risk of a mistaken match. U.S. charging materials cited in the case accuse an Aleksandr Ermakov of involvement in Sodinokibi/REvil attacks from April 2019 to July 2021, with the Interpol notice reportedly describing a platform administrator who earned more than $13.7 million and whose operations hit more than 1,000 organizations, including businesses, government offices, schools, and hospitals. Defense lawyers also suggested automated matching may have contributed to the detention, while Armenian authorities and the U.S. Justice Department had not publicly clarified the identity issue at the time of reporting.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.