Sodinokibi, also known as REvil, is a ransomware family first observed in the wild in late April 2019 and operated as a Ransomware-as-a-Service (RaaS) scheme. Core developers maintained the malware while affiliates conducted intrusions and deployment. Reported initial access vectors included exploitation of Oracle WebLogic Server vulnerabilities, phishing, exploit kits, brute-forced or otherwise compromised RDP, and targeted intrusions with lateral execution inside victim networks. Multiple investigated campaigns began with breaches of RDP servers.
Technically, analyzed samples were described as packed 32-bit binaries, with a Visual C++ packer and a ransomware payload written in assembly. The packer decrypts the payload and executes it from memory via RunPE. The malware dynamically resolves APIs, creates a hardcoded mutex to enforce single-instance execution, and decrypts an embedded JSON configuration protected by a CRC32-based integrity check. Configuration fields were reported to control attacker public key material, affiliate and campaign identifiers, debugging and speed options, wiping behavior, whitelists, folders to wipe, processes to terminate, C2/telemetry domains, ransom note and wallpaper templates, and an exploit option.
The malware can attempt privilege escalation using CVE-2018-8453 and may also relaunch itself with runas when elevated privileges are needed. It checks OS version information and file timestamps to assess exploitability, uses different shellcode for 32-bit and 64-bit targets, and may use Heaven’s Gate for 64-bit execution from a 32-bit process. If running as SYSTEM, it may impersonate the Explorer.exe user token.
For victim identification and state tracking, Sodinokibi generates a victim ID using disk serial number and CRC32-derived values, obtains processor identification via CPUID, and stores multiple values under a registry subkey typically SOFTWARE\recfg, including 0_key, sk_key, pk_key, subkey, stat, and rnd_ext. It first attempts to write under HKEY_LOCAL_MACHINE and falls back to HKEY_CURRENT_USER.
Behaviorally, Sodinokibi deletes shadow copies and weakens recovery boot settings using vssadmin and bcdedit, encrypts files on local logical drives and network shares while honoring configured whitelists, drops ransom notes, and may change the desktop wallpaper. If configured, it can terminate specified processes, wipe specified folders, and exfiltrate victim information via HTTP POST to configured domains. It also cleans sensitive strings and variables from memory to hinder RAM forensics.
A notable safeguard is a language blacklist: the malware checks system language and exits without action if blacklisted languages are detected, including Russian, Ukrainian, Belarusian, and Syrian variants.
McAfee assessed roughly 40% code overlap between Sodinokibi and GandCrab v5.03 and concluded the developers likely had access to GandCrab source code or a derivative/leaked codebase. The operation later dissolved following the Kaseya attack and subsequent law enforcement intervention, and its affiliates were reported to have migrated to other major RaaS operations including Conti and LockBit 2.0. In Q3 2021, Sodinokibi remained one of the prevalent ransomware variants. Reported detections included the names Ransom-Sodinokibi and Ransom-REvil.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Sodinokibi (REvil) is a high-profile ransomware-as-a-service operation responsible for major attacks, including the Kaseya incident, and is known for double extortion tactics.
Sodinokibi (REvil) is a sophisticated ransomware family operating as a Ransomware-as-a-Service (RaaS). It encrypts files on victim systems and demands payment for decryption. It is distributed by affiliates using various methods, including exploiting vulnerabilities, phishing, and brute-forcing RDP. The malware is highly configurable, can wipe files, and avoids systems with certain language settings. It shares significant code overlap with GandCrab, suggesting a relationship between the two.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.