Last seven days
- First activity
- Aug 8, 2026
- Last activity
- Aug 8, 2026
- Feed role
- C2 / Distribution
- Host form
- 5 IP / 12 hostnames
REvil, also known as Sodinokibi and sometimes Sodin, was a Russia-based financially motivated ransomware-as-a-service operation active primarily from 2019 through 2021.
Profile source: Mallory opens in a new tabREvil
REvil, also known as Sodinokibi and sometimes Sodin, was a Russia-based financially motivated ransomware-as-a-service operation active primarily from 2019 through 2021. It is widely regarded as a successor to GandCrab and became one of the most prominent double-extortion ransomware groups of its era. REvil combined file encryption with theft of victim data and public leak-site pressure, threatening publication or auction of stolen information to coerce payment. The group targeted a broad range of sectors worldwide, including private companies, government entities, law enforcement, schools, hospitals, managed service providers, and law firms.
REvil operated through an affiliate model in which core operators maintained the ransomware platform and supporting infrastructure while affiliates conducted intrusions and deployments. Reporting has linked the group to more than 1,000 victims during its main period of activity. The operation was associated with large ransom demands and aggressive extortion tactics, including escalating demands when victims refused to pay and publicizing sensitive stolen data to increase pressure. High-profile incidents attributed to REvil include the 2021 Kaseya VSA supply-chain attack, which leveraged a zero-day vulnerability to distribute ransomware through managed service provider infrastructure at scale, and the 2020 intrusion into entertainment law firm Grubman Shire Meiselas & Sacks, where celebrity-related data was used as extortion leverage.
Tactically, REvil used enterprise intrusion tradecraft common to major ransomware crews of the period. Observed behaviors include data exfiltration prior to encryption, use of leak sites and countdown timers for coercion, and defense evasion through techniques such as DLL sideloading. One documented example involved abuse of a legitimate Windows Defender component to load a malicious DLL containing ransomware. REvil has also been associated with Linux and ESXi-focused locker development, including references to a Revix ESXi locker, reflecting the broader shift by major ransomware groups toward virtualization infrastructure.
REvil played a significant role in normalizing and popularizing double extortion alongside groups such as Maze, influencing later ransomware ecosystems. Its name continued to surface after its peak because former affiliates and members were reported in connection with later ransomware operations, and some reporting has suggested overlap or migration of personnel into other Russia-linked criminal groups. Russian authorities later announced arrests and prosecutions of individuals tied to REvil, though reporting has also noted comparatively lenient outcomes in some cases. Overall, REvil remains one of the defining ransomware brands of the early 2020s and a major reference point in the evolution of industrialized ransomware operations.
C2 tracking
Derp observations, rolling seven-day window
Samples
36b43e8350bc4890bbba8c1be515fd4e7468ef932dd1c73b3244575f1197075a 3e6f7f9456ae9906e40da831c58f9b78a2eee8af2682cac7a9abf1a854142aa0 75911dc6fa5d482feb87fb96a1e2733395312459aa9096e2e78f54bb1090a7f4 e98f6a17fd2c3926f435e4a4ddf8954250a383d7485ab5c74609916ec4dfc63d 0049bd68937a94dc047a1ad06222fceb30315d6d26546a9a2665453045bd8403 04bbb2229d812b5b196b55aaae247e2adf8759b19a2f5411fbe670ace8147121 1b357f661479133d97cfd89fec1a6852f78c3ba86cde9c8325c6e5c91a437695 1eb56716cb68e28799b9d476eaab2ed389d16ff77a88d63140779bbc47f40456 2946b931ce28aabbb03881f8671892a6c6a4b9a8fad67b8a0fb75497de27e439 2fb21fa13c308228ae89c000cc1f9aa488cb010478ba8d15de372a0fbf37f1fb MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.