REvil, also known as Sodin and Sodinokibi, is a financially motivated ransomware operation associated with high-profile double-extortion campaigns. The group is known for deploying ransomware to encrypt victim files while also stealing sensitive data and threatening public release to coerce payment. REvil has publicly pressured both direct victims and their customers, including using leak-site postings to amplify extortion demands and increase reputational and commercial pressure. The operation has been linked to intrusions affecting major technology supply-chain targets and other large enterprises. In one notable campaign, the group claimed theft of confidential product plans from Quanta Computer and attempted to extort Apple by threatening staged publication of stolen materials. REvil has also been cited alongside other major ransomware groups as an example of operators that expanded beyond encryption into broader extortion models centered on data theft and public shaming. REvil’s core capabilities directly supported here are initial access, data exfiltration, and extortion through stolen-data exposure. Its tradecraft reflects a mature ransomware enterprise model in which theft of sensitive information is used as leverage even when victims may be able to recover encrypted systems from backups. Known aliases include Sodin and Sodinokibi.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as another ransomware operator associated with double and triple extortion tactics.
Ransomware and data-extortion operation that stole confidential product plans from Quanta Computer and threatened to publish them to extort payment, including pressuring Apple after Quanta allegedly refused to pay.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.