Skip to content

REvil

REvil, also known as Sodinokibi or Sodin, was a ransomware-as-a-service operation in which core operators maintained the ransomware and payment infrastructure while affiliates conducted intrusions and deployed encryptors in corporate environments.

Profile source: Mallory opens in a new tab

REvil

Family profile

REvil, also known as Sodinokibi or Sodin, was a ransomware-as-a-service operation in which core operators maintained the ransomware and payment infrastructure while affiliates conducted intrusions and deployed encryptors in corporate environments. The operation used file encryption, data theft and threatened disclosure as double-extortion mechanisms, and offered additional pressure tactics including distributed denial-of-service attacks and voice-scrambled calls to victims’ partners and journalists. REvil activity included exfiltration of victim data to cloud-storage services and deployment through compromised remote-management infrastructure, notably the 2021 Kaseya VSA supply-chain incident. The Kaseya-related payload used DLL sideloading and avoided systems configured for Russian and certain Commonwealth of Independent States languages. REvil developed a Linux encryptor intended to target VMware ESXi virtual-machine environments, in addition to Windows systems. Russian authorities announced arrests and disruption of an alleged REvil-associated criminal group in January 2022, although defendants reportedly denied affiliation.

Capabilities

  • Ddos
  • Defense Evasion
  • Dll Sideloading
  • Exfiltration
  • Extortion

Operational record

1
YARA rules
3
Ransom notes
20
Negotiations
3
Leak sites
0 available

Discovery Enum

  • AdFind
  • Bloodhound

Exfiltration

  • PrivatLab
  • RClone
  • Sendspace

LOLBAS

  • BITSAdmin

Offsec

  • Cobalt Strike

Reported operators

Threat actors

20 named in public reporting
REvil Ransomware group

Kaseya released security patches for multiple vulnerabilities impacting the Kaseya VSA product, that was actively exploited in the recent REvil ransomware campaign.

Bassterlord

Bassterlord, a suspected Russian-speaking threat actor who previously served as an affiliate for the LockBit ransomware gang, but also other rival RaaS operations, such as REvil, Avaddon, and RansomExx.

REvil

The U.S. Department of Justice today announced the arrest of Ukrainian man accused of deploying ransomware on behalf of the REvil ransomware gang, a Russian-speaking cybercriminal collective that has extorted hundreds of millions from victim organizations.

FIN7

L’affiliation de FIN7 au RaaS Sodinokibi courant 2020 a par la suite été confirmée.

GOLD SOUTHFIELD

L’affiliation de FIN7 au RaaS Sodinokibi courant 2020 a par la suite été confirmée.

National Hazard Agency

Bassterlord partnered with at least four ransomware gangs: REvil, RansomEXX, Avadon and LockBit.

lalartu

Bassterlord partnered with at least four ransomware gangs: REvil, RansomEXX, Avadon and LockBit.

Carbanak

REvil (short for Ransomware Evil) is a revolutionary ransomware operation... Kaseya warned customers to immediately shut down their VSA server as REvil ransomware was spreading through its auto-update function.

CarbonSpider

REvil (short for Ransomware Evil) is a revolutionary ransomware operation... Kaseya warned customers to immediately shut down their VSA server as REvil ransomware was spreading through its auto-update function.

PinchySpider

REvil (short for Ransomware Evil) is a revolutionary ransomware operation... Kaseya warned customers to immediately shut down their VSA server as REvil ransomware was spreading through its auto-update function.

Leafroller

Several hundred organizations have been targeted by the REvil (aka Sodinokibi) ransomware in a supply chain attack involving Kaseya VSA software and multiple Managed Service Providers (MSPs) who use it.

REvil ransomware gang

The universal decryption key for REvil's attack on Kaseya's customers has been leaked on hacking forums... On July 2nd, the REvil ransomware gang launched a massive attack on managed service providers worldwide by exploiting a zero-day vulnerability in the Kaseya VSA remote management application.

Prometheus

In the blog, the group has affiliated itself with the REvil ransomware group.

UNKN

REvil aka Sodinokibi, Sodin is a ransomware family operated as a ransomware-as-a-service (RaaS). Deployments of REvil first were observed in April 2019, where attackers leveraged a vulnerability in Oracle WebLogic servers tracked as CVE-2019-2725.

Velvet Tempest

In 2020 ELBRUS transitioned from using PoS malware to deploying ransomware as part of a financially motivated extortion scheme, specifically deploying the MAZE and Revil RaaS families.

INDRIK SPIDER

One group known for pivoting is Evil Corp., the gang behind Revil. Revil’s tactics align with why a threat group would target an insurance provider.

DEV-0216

In 2020 ELBRUS transitioned from using PoS malware to deploying ransomware as part of a financially motivated extortion scheme, specifically deploying the MAZE and Revil RaaS families.

UNC2628

UNC2628 is thought to partner with other RaaS services including REvil and Netwalker.

Lockean

Between June 2020 and March 2021, Lockean attacked at least seven more companies with various ransomware families: Maze, Egregor, ProLock, REvil.

OnePercent

Between June 2020 and March 2021, Lockean attacked at least seven more companies with various ransomware families: Maze, Egregor, ProLock, REvil.

Exploited software

Vulnerabilities linked to REvil

11 CVEs

MITRE ATT&CK

REvil in ATT&CK

110 distinct techniques

Techniques

110 techniques
T1195 Supply Chain Compromise T1657 Financial Theft T1041 Exfiltration Over C2 Channel T1486 Data Encrypted for Impact T1567 Exfiltration Over Web Service T1562 Impair Defenses T1562.001 Disable or Modify Tools T1105 Ingress Tool Transfer T1189 Drive-by Compromise T1072 Software Deployment Tools T1489 Service Stop T1548.002 Bypass User Account Control T1059.001 PowerShell T1537 Transfer Data to Cloud Account T1614.001 System Language Discovery T1497 Virtualization/Sandbox Evasion T1112 Modify Registry T1070.004 File Deletion T1566.001 Spearphishing Attachment T1027.013 Encrypted/Encoded File T1082 System Information Discovery T1059.005 Visual Basic T1680 Local Storage Discovery T1071.001 Web Protocols T1106 Native API T1083 File and Directory Discovery T1059.003 Windows Command Shell T1036 Masquerading T1140 Deobfuscate/Decode Files or Information T1218.010 Regsvr32 T1573.002 Asymmetric Cryptography T1134.002 Create Process with Token T1190 Exploit Public-Facing Application T1485 Data Destruction T1534 Internal Spearphishing T1204.002 Malicious File T1567.003 Exfiltration to Text Storage Sites T1480.002 Mutual Exclusion T1490 Inhibit System Recovery T1055 Process Injection T1069.002 Domain Groups T1204 User Execution T1036.005 Match Legitimate Resource Name or Location T1021 Remote Services T1012 Query Registry T1047 Windows Management Instrumentation T1027.011 Fileless Storage T1134.001 Token Impersonation/Theft T1007 System Service Discovery T1199 Trusted Relationship T1133 External Remote Services T1016 System Network Configuration Discovery T1574.001 DLL T1018 Remote System Discovery T1027 Obfuscated Files or Information T1057 Process Discovery T1021.002 SMB/Windows Admin Shares T1021.001 Remote Desktop Protocol T1547.001 Registry Run Keys / Startup Folder T1482 Domain Trust Discovery T1003 OS Credential Dumping T1218 System Binary Proxy Execution T1491.001 Internal Defacement T1203 Exploitation for Client Execution T1218.002 Control Panel T1078 Valid Accounts T1071 Application Layer Protocol T1055.012 Process Hollowing T1046 Network Service Discovery T1484.001 Group Policy Modification T1570 Lateral Tool Transfer T1566 Phishing T1568 Dynamic Resolution T1068 Exploitation for Privilege Escalation T1498 Network Denial of Service T1622 Debugger Evasion T1620 Reflective Code Loading T1059 Command and Scripting Interpreter T1569 System Services T1053 Scheduled Task/Job T1566.002 Spearphishing Link T1491 Defacement T1562.009 Safe Mode Boot T1059.007 JavaScript T1027.007 Dynamic API Resolution T1497.001 System Checks T1110 Brute Force T1608.006 SEO Poisoning T1529 System Shutdown/Reboot T1020 Automated Exfiltration T1568.002 Domain Generation Algorithms T1074 Data Staged T1135 Network Share Discovery T1134 Access Token Manipulation T1583 Acquire Infrastructure T1110.003 Password Spraying T1003.001 LSASS Memory T1598 Phishing for Information T1136 Create Account T1567.002 Exfiltration to Cloud Storage T1090 Proxy T1033 System Owner/User Discovery T1587.004 Exploits T1219 Remote Access Tools T1505.003 Web Shell T1553.002 Code Signing T1210 Exploitation of Remote Services T1552 Unsecured Credentials T1218.003 CMSTP T1218.007 Signed Binary Proxy Execution: Msiexec

Reporting

Research mentioning REvil

Aug 31
Malware News

ValleyRAT masquerading as adware - Malware News - Malware Analysis, News and Indicators

A malicious installer posing as signed QN Wallpaper adware is deploying the ValleyRAT backdoor by DLL sideloading a trojanized libcef.dll through QnWallpaper.exe or QnwPlayer.exe. The malware disables Microsoft Defender, establishes persistence, decrypts and reflectively loads its payloads, and selects command-and-control configurations based on the host executable. ValleyRAT supports surveillance, host reconnaissance, anti-analysis, process protection, command execution, and delivery of additional modules. Kaspersky recorded more than 100,000 detections affecting over 1,500 unique users during 2026, primarily in China and India. The campaign abuses a signed legitimate application to evade security controls—a DLL-sideloading pattern used by both advanced persistent threat and ransomware actors—and its geography and ValleyRAT use indicate that Silver Fox is the likely operator.

Aug 31
Securelist

ValleyRAT is spreading disguised as adware | Securelist

Aug 20
Hookphish

Ransomware Group qilin Hits: Trends And Concepts

Researchers reported that the Agenda ransomware operation, also tracked as Qilin, is conducting highly customized enterprise attacks across Asia and Africa and has now been linked to a victim in South Africa. A recent victim listing identified Trends And Concepts in South Africa, associated with the domain www.trendsandconceptsinteriors.com, as impacted by the Qilin group. Trend researchers said Agenda operators build victim-specific Go-based payloads that can include leaked account credentials, unique company identifiers, customized RSA keys, and ransom demands ranging from $50,000 to $800,000, with observed targeting of healthcare and education organizations in Indonesia, Saudi Arabia, South Africa, and Thailand. The intrusion methods described across the reports show a flexible and increasingly sophisticated playbook. In one case, attackers accessed a public-facing Citrix server using a valid account, moved laterally with RDP and leaked Active Directory credentials, scanned networks with Nmap and Nping, and deployed ransomware through Group Policy in under two days. A separate Trend investigation found Agenda actors using fake Google CAPTCHA pages to deliver credential stealers, then abusing legitimate remote-management tools including ATERA, AnyDesk, ScreenConnect, and Splashtop, while deploying COROXY SOCKS proxies, targeting Veeam backup infrastructure, and using BYOVD techniques with vulnerable drivers such as eskle.sys; the final ransomware payload was reportedly a Linux variant executed on Windows, likely through Windows Subsystem for Linux.

Aug 20
Splunk Research

Detection: Windows Phantom DLL Created on Disk | Splunk Security Content

NightmareEclipse released ShieldBreak, a proof-of-concept local privilege-escalation exploit claimed to bypass Microsoft’s fix for CVE-2026-50656 (RoguePlanet). The exploit allegedly abuses improper link resolution during Windows Defender remediation, combining Cloud Files placeholders, Object Manager symbolic-link swaps, CLFS path handling, an EICAR-triggered scan, and NTFS alternate data streams to redirect a Defender process running as SYSTEM and plant C:\Windows\System32\phoneinfo.dll. A fabricated Windows Error Reporting report and the QueueReporting scheduled task then cause wermgr.exe to load the malicious DLL; the included Warden.dll payload reportedly duplicates a SYSTEM token and opens a SYSTEM shell in the unprivileged user’s session. Splunk published attack data and multiple disabled-by-default analytics for the ShieldBreak chain, covering Defender activity on \globalroot\ object-manager paths (Defender Operational events 1116/1117), MpClient.dll loaded by non-Defender processes, ADS creation through loopback administrative SMB shares (Security event 5145), manually created .wer files in the Windows Error Reporting ReportQueue, creation of phantom DLLs such as phoneinfo.dll in system paths, and WerMgr.exe spawning SYSTEM-integrity children. Organizations should collect the required Sysmon, Security, and Defender Operational telemetry; enable file-share object-access auditing; investigate these signals promptly; and validate the creating process, signer, file hash, and operational need before suppressing alerts.

Aug 19
Splunk Research

Detection: Windows Defender MpClient.dll Loaded by Non-Defender Process | Splunk Security Content

Aug 19
Splunk Research

Detection: Windows Alternate Data Stream Created Over Local Share | Splunk Security Content

Aug 19
Trendai Security

Agenda Ransomware Deploys Linux Variant on Windows Systems Through Remote Management Tools and BYOVD Techniques | TrendAI (US)

Aug 18
Splunk Research

Detection: Windows Defender Threat Detected on Kernel Object Path | Splunk Security Content

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.