Skip to content

REvil

REvil, also known as Sodinokibi or Sodin, is a Windows ransomware family and ransomware-as-a-service operation that was among the most prolific extortion threats of the early 2020s.

Profile source: Mallory opens in a new tab

REvil

Family profile

REvil, also known as Sodinokibi or Sodin, is a Windows ransomware family and ransomware-as-a-service operation that was among the most prolific extortion threats of the early 2020s. It is associated with large-scale double-extortion campaigns in which victim data is stolen prior to encryption and payment is demanded for both decryption and non-disclosure. Reported victimology spans private companies, government offices, schools, hospitals, law enforcement entities, and managed service provider downstream customers.

REvil is known for enterprise-focused intrusion activity and for excluding certain systems based on language settings, terminating execution when the host language matches entries in its internal exclusion list. The malware can query and modify the Windows Registry, including storing encryption parameters and runtime configuration artifacts there. It appends randomized encrypted-file extensions, gathers system information, and uses robust asymmetric and symmetric cryptographic routines during file encryption.

Operationally, REvil has been linked to high-impact supply-chain abuse, most notably the July 2021 compromise of on-premises Kaseya VSA servers, where attackers exploited a code-injection vulnerability to distribute the ransomware through managed service provider infrastructure to downstream endpoints. In that intrusion chain, the payload was executed via DLL sideloading after security controls were disabled. REvil has also been referenced as a technical predecessor or code relative of later ransomware families, with multiple researchers noting substantial overlaps between REvil and Ransom Cartel, including encryption workflow, configuration structure, and session-secret generation, while also observing that later derivatives appeared to lack REvil’s full obfuscation capability.

The operation has been widely tracked as a major Russian-speaking cybercriminal ransomware ecosystem. Public reporting has tied alleged members and administrators to attacks conducted from 2019 through 2021, with more than 1,000 victims attributed in charging materials. REvil’s prominence, technical maturity, and role in major extortion and supply-chain incidents made it a defining ransomware threat of its era.

Capabilities

  • Defense Evasion
  • Exfiltration

Operational record

1
YARA rules
3
Ransom notes
20
Negotiations
3
Leak sites
0 available

Discovery Enum

  • AdFind
  • Bloodhound

Exfiltration

  • PrivatLab
  • RClone
  • Sendspace

LOLBAS

  • BITSAdmin

Offsec

  • Cobalt Strike

Reported operators

Threat actors

10 named in public reporting
UNKN

REvil aka Sodinokibi, Sodin is a ransomware family operated as a ransomware-as-a-service (RaaS). Deployments of REvil first were observed in April 2019, where attackers leveraged a vulnerability in Oracle WebLogic servers tracked as CVE-2019-2725.

FIN7

In 2023, FIN7 expanded its operations to include the deployment of ransomware through affiliations with RaaS groups such as REvil and Maze, while also managing its own RaaS programs, including the now-retired Darkside and BlackMatter.

Velvet Tempest

In 2020 ELBRUS transitioned from using PoS malware to deploying ransomware as part of a financially motivated extortion scheme, specifically deploying the MAZE and Revil RaaS families.

INDRIK SPIDER

One group known for pivoting is Evil Corp., the gang behind Revil. Revil’s tactics align with why a threat group would target an insurance provider.

DEV-0216

In 2020 ELBRUS transitioned from using PoS malware to deploying ransomware as part of a financially motivated extortion scheme, specifically deploying the MAZE and Revil RaaS families.

UNC2628

UNC2628 is thought to partner with other RaaS services including REvil and Netwalker.

Lockean

Between June 2020 and March 2021, Lockean attacked at least seven more companies with various ransomware families: Maze, Egregor, ProLock, REvil.

OnePercent

Between June 2020 and March 2021, Lockean attacked at least seven more companies with various ransomware families: Maze, Egregor, ProLock, REvil.

GOLD SOUTHFIELD

GOLD SOUTHFIELD has used the cloud-based remote management and monitoring tool "ConnectWise Control" to deploy REvil.

REvil

"REvil, also known as Sodinokibi, emerged in 2019 and is widely believed to have evolved out of the GandCrab ransomware group."

Exploited software

Vulnerabilities linked to REvil

6 CVEs

MITRE ATT&CK

REvil in ATT&CK

89 distinct techniques

Techniques

89 techniques
T1486 Data Encrypted for Impact T1027 Obfuscated Files or Information T1497 Virtualization/Sandbox Evasion T1218.010 Regsvr32 T1195 Supply Chain Compromise T1562 Impair Defenses T1562.001 Disable or Modify Tools T1059.001 PowerShell T1140 Deobfuscate/Decode Files or Information T1036 Masquerading T1070.004 File Deletion T1203 Exploitation for Client Execution T1105 Ingress Tool Transfer T1059.003 Windows Command Shell T1112 Modify Registry T1574.001 DLL T1021 Remote Services T1657 Financial Theft T1012 Query Registry T1614.001 System Language Discovery T1082 System Information Discovery T1565 Data Manipulation T1489 Service Stop T1548.002 Bypass User Account Control T1027.007 Dynamic API Resolution T1135 Network Share Discovery T1057 Process Discovery T1068 Exploitation for Privilege Escalation T1027.002 Software Packing T1547.001 Registry Run Keys / Startup Folder T1071.001 Web Protocols T1497.001 System Checks T1041 Exfiltration Over C2 Channel T1490 Inhibit System Recovery T1190 Exploit Public-Facing Application T1480.002 Mutual Exclusion T1083 File and Directory Discovery T1204.002 Malicious File T1567.002 Exfiltration to Cloud Storage T1055.012 Process Hollowing T1078 Valid Accounts T1119 Automated Collection T1053 Scheduled Task/Job T1218 System Binary Proxy Execution T1620 Reflective Code Loading T1573 Encrypted Channel T1059 Command and Scripting Interpreter T1047 Windows Management Instrumentation T1033 System Owner/User Discovery T1566.001 Spearphishing Attachment T1027.013 Encrypted/Encoded File T1588.001 Malware T1204 User Execution T1055 Process Injection T1133 External Remote Services T1102 Web Service T1048 Exfiltration Over Alternative Protocol T1567 Exfiltration Over Web Service T1074 Data Staged T1090.003 Multi-hop Proxy T1491.001 Internal Defacement T1537 Transfer Data to Cloud Account T1210 Exploitation of Remote Services T1570 Lateral Tool Transfer T1219 Remote Access Tools T1587 Develop Capabilities T1027.011 Fileless Storage T1573.002 Asymmetric Cryptography T1543 Create or Modify System Process T1562.009 Safe Mode Boot T1482 Domain Trust Discovery T1485 Data Destruction T1548 Abuse Elevation Control Mechanism T1059.005 Visual Basic T1069.002 Domain Groups T1562.007 Disable or Modify Cloud Firewall T1007 System Service Discovery T1106 Native API T1036.005 Match Legitimate Resource Name or Location T1071 Application Layer Protocol T1189 Drive-by Compromise T1134.001 Token Impersonation/Theft T1134.002 Create Process with Token T1070.001 Clear Windows Event Logs T1491 Defacement T1680 Local Storage Discovery T1218.007 Signed Binary Proxy Execution: Msiexec T1003.001 OS Credential Dumping: LSASS Memory T1021.001 Remote Services: Remote Desktop Protocol

Reporting

Research mentioning REvil

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.