REvil, also known as Sodinokibi and sometimes Sodin, was a Russia-based financially motivated ransomware-as-a-service operation active primarily from 2019 through 2021. It is widely regarded as a successor to GandCrab and became one of the most prominent double-extortion ransomware groups of its era. REvil combined file encryption with theft of victim data and public leak-site pressure, threatening publication or auction of stolen information to coerce payment. The group targeted a broad range of sectors worldwide, including private companies, government entities, law enforcement, schools, hospitals, managed service providers, and law firms. REvil operated through an affiliate model in which core operators maintained the ransomware platform and supporting infrastructure while affiliates conducted intrusions and deployments. Reporting has linked the group to more than 1,000 victims during its main period of activity. The operation was associated with large ransom demands and aggressive extortion tactics, including escalating demands when victims refused to pay and publicizing sensitive stolen data to increase pressure. High-profile incidents attributed to REvil include the 2021 Kaseya VSA supply-chain attack, which leveraged a zero-day vulnerability to distribute ransomware through managed service provider infrastructure at scale, and the 2020 intrusion into entertainment law firm Grubman Shire Meiselas & Sacks, where celebrity-related data was used as extortion leverage. Tactically, REvil used enterprise intrusion tradecraft common to major ransomware crews of the period. Observed behaviors include data exfiltration prior to encryption, use of leak sites and countdown timers for coercion, and defense evasion through techniques such as DLL sideloading. One documented example involved abuse of a legitimate Windows Defender component to load a malicious DLL containing ransomware. REvil has also been associated with Linux and ESXi-focused locker development, including references to a Revix ESXi locker, reflecting the broader shift by major ransomware groups toward virtualization infrastructure. REvil played a significant role in normalizing and popularizing double extortion alongside groups such as Maze, influencing later ransomware ecosystems. Its name continued to surface after its peak because former affiliates and members were reported in connection with later ransomware operations, and some reporting has suggested overlap or migration of personnel into other Russia-linked criminal groups. Russian authorities later announced arrests and prosecutions of individuals tied to REvil, though reporting has also noted comparatively lenient outcomes in some cases. Overall, REvil remains one of the defining ransomware brands of the early 2020s and a major reference point in the evolution of industrialized ransomware operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
30 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
The threat actors behind the DearCry ransomware have already used the ProxyLogon vulnerability to deploy their ransomware...
The 2021 Kaseya VSA compromise by REvil used several zero-day vulnerabilities, including CVE-2021-30116 and CVE-2021-30120, which allowed them to bypass authentication requirements to access VSA servers en route to deploying ransomware in up to 1500 downstream client networks.
The 2021 Kaseya VSA compromise by REvil used several zero-day vulnerabilities, including CVE-2021-30116 and CVE-2021-30120, which allowed them to bypass authentication requirements to access VSA servers en route to deploying ransomware in up to 1500 downstream client networks.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware operations that impacted over 1,000 entities, including private companies, government offices, schools, and hospitals, during the period between April 2019 and July 2021.
Ransomware operation tied in the article to widespread attacks between 2019 and 2021, with allegations that one administrator took over $13.7 million and that the group had more than 1,000 victims across private and public-sector organizations.
Conducted a targeted ransomware/extortion operation against a law firm serving entertainment clients, using selective leaks and escalating ransom demands to maximize public pressure.
Weaponized DLL sideloading for ransomware delivery by abusing a legitimate Windows Defender executable.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.