REvil, also known as Sodinokibi and Sodin, was a financially motivated ransomware-as-a-service operation. Its core operators supplied ransomware, payment infrastructure, negotiation, data-management, and helpdesk services, while affiliates conducted intrusions and deployed payloads against victim organizations. REvil conducted big-game ransomware and extortion operations, including the July 2021 supply-chain compromise involving Kaseya VSA. The operation targeted enterprise Windows environments and developed a Linux encryptor designed to impact VMware ESXi virtualized infrastructure. REvil used data theft alongside file encryption, operated a leak-oriented extortion model, and reportedly auctioned stolen victim data. It expanded coercion through DDoS attacks and voice-based pressure campaigns aimed at media outlets and victims’ business partners. Observed access activity included reconnaissance for vulnerable VPN infrastructure, while the Kaseya campaign used abuse of a legitimate security product and DLL sideloading to hinder detection. REvil ransomware samples associated with the Kaseya campaign avoided systems configured for Russian and certain Commonwealth of Independent States languages; this behavior does not by itself establish the operators’ geographic origin.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
57 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
11 CVEs this actor has used in observed campaigns. 11 of them exploited in the wild.
Patched vulnerabilities are as follows: CVE-2021-30116: Credentials leak and business logic flaw
Patched vulnerabilities are as follows: CVE-2021-30120: Two Factor Authentication (2FA) bypass
Evidence points to the DDoS attacks coming from the massive Meris botnet. Meris sucks its power out of the thousands of internet-of-things (IoT) devices that have been hijacked thanks to a years-old vulnerability, tracked as CVE-2018-14847, in MicroTik routers.
Vulnerabilities Actively Exploited by Ransomware Threats: CVE-2019-11510 (Pulse Secure)
Vulnerabilities Actively Exploited by Ransomware Threats: CVE-2019-11539 (Pulse Secure)
6 more CVEs tied to this actor tracked in Mallory.
45 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Упоминается как ransomware family/codebase, с которым сравнивали малварь Ransom Cartel; предполагается возможная связь через бывшего участника REvil.
Referenced as another ransomware group that went dark under law-enforcement pressure.
Conducted a large-scale ransomware supply-chain attack via Kaseya VSA, compromising MSPs and downstream customers; known for prolific ransomware operations, affiliate-based attacks, and extortion.
Mentioned as a comparative example of another ransomware operation running an affiliate program.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.