Discovery Enum
- AdFind
- Bloodhound
REvil, also known as Sodinokibi or Sodin, was a ransomware-as-a-service operation in which core operators maintained the ransomware and payment infrastructure while affiliates conducted intrusions and deployed encryptors in corporate environments.
Profile source: Mallory opens in a new tabREvil
REvil, also known as Sodinokibi or Sodin, was a ransomware-as-a-service operation in which core operators maintained the ransomware and payment infrastructure while affiliates conducted intrusions and deployed encryptors in corporate environments. The operation used file encryption, data theft and threatened disclosure as double-extortion mechanisms, and offered additional pressure tactics including distributed denial-of-service attacks and voice-scrambled calls to victims’ partners and journalists. REvil activity included exfiltration of victim data to cloud-storage services and deployment through compromised remote-management infrastructure, notably the 2021 Kaseya VSA supply-chain incident. The Kaseya-related payload used DLL sideloading and avoided systems configured for Russian and certain Commonwealth of Independent States languages. REvil developed a Linux encryptor intended to target VMware ESXi virtual-machine environments, in addition to Windows systems. Russian authorities announced arrests and disruption of an alleged REvil-associated criminal group in January 2022, although defendants reportedly denied affiliation.
Reported operators
Kaseya released security patches for multiple vulnerabilities impacting the Kaseya VSA product, that was actively exploited in the recent REvil ransomware campaign.
Bassterlord, a suspected Russian-speaking threat actor who previously served as an affiliate for the LockBit ransomware gang, but also other rival RaaS operations, such as REvil, Avaddon, and RansomExx.
The U.S. Department of Justice today announced the arrest of Ukrainian man accused of deploying ransomware on behalf of the REvil ransomware gang, a Russian-speaking cybercriminal collective that has extorted hundreds of millions from victim organizations.
L’affiliation de FIN7 au RaaS Sodinokibi courant 2020 a par la suite été confirmée.
L’affiliation de FIN7 au RaaS Sodinokibi courant 2020 a par la suite été confirmée.
Bassterlord partnered with at least four ransomware gangs: REvil, RansomEXX, Avadon and LockBit.
Bassterlord partnered with at least four ransomware gangs: REvil, RansomEXX, Avadon and LockBit.
REvil (short for Ransomware Evil) is a revolutionary ransomware operation... Kaseya warned customers to immediately shut down their VSA server as REvil ransomware was spreading through its auto-update function.
REvil (short for Ransomware Evil) is a revolutionary ransomware operation... Kaseya warned customers to immediately shut down their VSA server as REvil ransomware was spreading through its auto-update function.
REvil (short for Ransomware Evil) is a revolutionary ransomware operation... Kaseya warned customers to immediately shut down their VSA server as REvil ransomware was spreading through its auto-update function.
Several hundred organizations have been targeted by the REvil (aka Sodinokibi) ransomware in a supply chain attack involving Kaseya VSA software and multiple Managed Service Providers (MSPs) who use it.
The universal decryption key for REvil's attack on Kaseya's customers has been leaked on hacking forums... On July 2nd, the REvil ransomware gang launched a massive attack on managed service providers worldwide by exploiting a zero-day vulnerability in the Kaseya VSA remote management application.
In the blog, the group has affiliated itself with the REvil ransomware group.
REvil aka Sodinokibi, Sodin is a ransomware family operated as a ransomware-as-a-service (RaaS). Deployments of REvil first were observed in April 2019, where attackers leveraged a vulnerability in Oracle WebLogic servers tracked as CVE-2019-2725.
In 2020 ELBRUS transitioned from using PoS malware to deploying ransomware as part of a financially motivated extortion scheme, specifically deploying the MAZE and Revil RaaS families.
One group known for pivoting is Evil Corp., the gang behind Revil. Revil’s tactics align with why a threat group would target an insurance provider.
In 2020 ELBRUS transitioned from using PoS malware to deploying ransomware as part of a financially motivated extortion scheme, specifically deploying the MAZE and Revil RaaS families.
UNC2628 is thought to partner with other RaaS services including REvil and Netwalker.
Between June 2020 and March 2021, Lockean attacked at least seven more companies with various ransomware families: Maze, Egregor, ProLock, REvil.
Between June 2020 and March 2021, Lockean attacked at least seven more companies with various ransomware families: Maze, Egregor, ProLock, REvil.
Exploited software
MITRE ATT&CK
Reporting
A malicious installer posing as signed QN Wallpaper adware is deploying the ValleyRAT backdoor by DLL sideloading a trojanized libcef.dll through QnWallpaper.exe or QnwPlayer.exe. The malware disables Microsoft Defender, establishes persistence, decrypts and reflectively loads its payloads, and selects command-and-control configurations based on the host executable. ValleyRAT supports surveillance, host reconnaissance, anti-analysis, process protection, command execution, and delivery of additional modules. Kaspersky recorded more than 100,000 detections affecting over 1,500 unique users during 2026, primarily in China and India. The campaign abuses a signed legitimate application to evade security controls—a DLL-sideloading pattern used by both advanced persistent threat and ransomware actors—and its geography and ValleyRAT use indicate that Silver Fox is the likely operator.
Researchers reported that the Agenda ransomware operation, also tracked as Qilin, is conducting highly customized enterprise attacks across Asia and Africa and has now been linked to a victim in South Africa. A recent victim listing identified Trends And Concepts in South Africa, associated with the domain www.trendsandconceptsinteriors.com, as impacted by the Qilin group. Trend researchers said Agenda operators build victim-specific Go-based payloads that can include leaked account credentials, unique company identifiers, customized RSA keys, and ransom demands ranging from $50,000 to $800,000, with observed targeting of healthcare and education organizations in Indonesia, Saudi Arabia, South Africa, and Thailand. The intrusion methods described across the reports show a flexible and increasingly sophisticated playbook. In one case, attackers accessed a public-facing Citrix server using a valid account, moved laterally with RDP and leaked Active Directory credentials, scanned networks with Nmap and Nping, and deployed ransomware through Group Policy in under two days. A separate Trend investigation found Agenda actors using fake Google CAPTCHA pages to deliver credential stealers, then abusing legitimate remote-management tools including ATERA, AnyDesk, ScreenConnect, and Splashtop, while deploying COROXY SOCKS proxies, targeting Veeam backup infrastructure, and using BYOVD techniques with vulnerable drivers such as eskle.sys; the final ransomware payload was reportedly a Linux variant executed on Windows, likely through Windows Subsystem for Linux.
NightmareEclipse released ShieldBreak, a proof-of-concept local privilege-escalation exploit claimed to bypass Microsoft’s fix for CVE-2026-50656 (RoguePlanet). The exploit allegedly abuses improper link resolution during Windows Defender remediation, combining Cloud Files placeholders, Object Manager symbolic-link swaps, CLFS path handling, an EICAR-triggered scan, and NTFS alternate data streams to redirect a Defender process running as SYSTEM and plant C:\Windows\System32\phoneinfo.dll. A fabricated Windows Error Reporting report and the QueueReporting scheduled task then cause wermgr.exe to load the malicious DLL; the included Warden.dll payload reportedly duplicates a SYSTEM token and opens a SYSTEM shell in the unprivileged user’s session. Splunk published attack data and multiple disabled-by-default analytics for the ShieldBreak chain, covering Defender activity on \globalroot\ object-manager paths (Defender Operational events 1116/1117), MpClient.dll loaded by non-Defender processes, ADS creation through loopback administrative SMB shares (Security event 5145), manually created .wer files in the Windows Error Reporting ReportQueue, creation of phantom DLLs such as phoneinfo.dll in system paths, and WerMgr.exe spawning SYSTEM-integrity children. Organizations should collect the required Sysmon, Security, and Defender Operational telemetry; enable file-share object-access auditing; investigate these signals promptly; and validate the creating process, signer, file hash, and operational need before suppressing alerts.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.