REvil, also known as Sodinokibi and Sodin, was a ransomware-as-a-service operation in which core operators maintained the ransomware and payment infrastructure while affiliates conducted intrusions and deployed payloads against organizations. It targeted corporate networks and employed encryption, data theft, and double- and triple-extortion pressure. Its operators offered affiliates additional coercive services including DDoS attacks and voice-scrambled calls to victims’ business partners and journalists.
REvil was associated with major enterprise incidents, including the July 2021 supply-chain compromise involving Kaseya VSA, where the ransomware was distributed through an abused software-update mechanism. The Kaseya-associated payload used DLL sideloading and excluded systems configured for Russian and other Commonwealth of Independent States languages. A campaign-specific decryption key later enabled recovery for files encrypted by the Kaseya-related REvil variant, but did not apply to other REvil infections.
REvil developed encryptors for Windows as well as Linux environments, including variants intended to affect VMware ESXi virtual machines. The operation was associated with data exfiltration before extortion and targeted organizations whose operational disruption and exposure of sensitive data could increase payment pressure. Russian authorities announced the dismantling of the REvil group in January 2022, although defendants in the subsequent case denied affiliation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Patched vulnerabilities are as follows: CVE-2021-30120: Two Factor Authentication (2FA) bypass | Kaseya released security patches for multiple vulnerabilities impacting the Kaseya VSA product, that was actively exploited in the recent REvil ransomware campaign.
Patched vulnerabilities are as follows: CVE-2021-30119: Cross-Site Scripting vulnerability | Kaseya released security patches for multiple vulnerabilities impacting the Kaseya VSA product, that was actively exploited in the recent REvil ransomware campaign.
Patched vulnerabilities are as follows: CVE-2021-30116: Credentials leak and business logic flaw | Kaseya released security patches for multiple vulnerabilities impacting the Kaseya VSA product, that was actively exploited in the recent REvil ransomware campaign.
The security researcher noted that all the Pulse Secure VPN servers included in the list were running a firmware version vulnerable to the CVE-2019-11510 vulnerability. Bank Security believes that the hacker who compiled this list scanned the entire internet IPv4 address space for Pulse Secure VPN servers, used an exploit for the CVE-2019-11510 vulnerability to gain access to systems, dump server details (including usernames and passwords), and then collected all the information in one central repository.
After execution, REvil can perform several steps, including: Attempting to escalate its privilege via CVE-2018-8453, or token impersonation and creating a mutex | We examine three major ransomware families that employ these schemes: REvil (aka Sodinokibi), Clop, and Conti.
Exploiting CVE-2018-13379, CVE-2019-11510, and valid accounts, which leads to the abuse of RDP and PsExec, and then the dropping of tools that disable antimalware, exfiltration tools, and, finally, REvil. | We examine three major ransomware families that employ these schemes: REvil (aka Sodinokibi), Clop, and Conti.
Exploiting CVE-2019-2725, which leads to the remote code execution of Certutil/PowerShell for downloading and executing REvil. | We examine three major ransomware families that employ these schemes: REvil (aka Sodinokibi), Clop, and Conti.
... as well as the BlueGate vulnerabilities affecting the Windows Remote Desktop Gateway (tracked as CVE-2020-0609 and CVE-2020-0610). | REvil (short for Ransomware Evil) is a revolutionary ransomware operation... Kaseya warned customers to immediately shut down their VSA server as REvil ransomware was spreading through its auto-update function.
... as well as the BlueGate vulnerabilities affecting the Windows Remote Desktop Gateway (tracked as CVE-2020-0609 and CVE-2020-0610). | REvil (short for Ransomware Evil) is a revolutionary ransomware operation... Kaseya warned customers to immediately shut down their VSA server as REvil ransomware was spreading through its auto-update function.
REvil’s BGH campaign has been successful in leveraging exploits for unpatched VPN products for initial access. This includes ... Citrix ADC gateway (CVE-2019-19781) ... | REvil (short for Ransomware Evil) is a revolutionary ransomware operation... Kaseya warned customers to immediately shut down their VSA server as REvil ransomware was spreading through its auto-update function.
Computer giant Acer has been hit by a REvil ransomware attack where the threat actors are demanding the largest known ransom to date, $50,000,000.
20 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Kaseya released security patches for multiple vulnerabilities impacting the Kaseya VSA product, that was actively exploited in the recent REvil ransomware campaign.
Bassterlord, a suspected Russian-speaking threat actor who previously served as an affiliate for the LockBit ransomware gang, but also other rival RaaS operations, such as REvil, Avaddon, and RansomExx.
The U.S. Department of Justice today announced the arrest of Ukrainian man accused of deploying ransomware on behalf of the REvil ransomware gang, a Russian-speaking cybercriminal collective that has extorted hundreds of millions from victim organizations.
L’affiliation de FIN7 au RaaS Sodinokibi courant 2020 a par la suite été confirmée.
L’affiliation de FIN7 au RaaS Sodinokibi courant 2020 a par la suite été confirmée.
Bassterlord partnered with at least four ransomware gangs: REvil, RansomEXX, Avadon and LockBit.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
GootLoader is an initial access malware... It is delivered through drive-by social engineering attacks.
The content repeatedly describes threat actors and malware using PowerShell to execute payloads, run commands, download additional malware, perform lateral movement, evade defenses, and execute scripts in memory. | Examples include: 'APT28 downloads and executes PowerShell scripts and performs PowerShell commands'; 'APT3 has used PowerShell on victim systems to download and run payloads after exploitation'; 'TA505 has used PowerShell to download and execute malware and reconnaissance scripts.'
There is a second option: To escalate using DelegateExecute... when an attempt is made to execute ComputerDefaults, we get a shell with scaled privileges. | It then makes use of CompMgmtLauncher and explorer.exe. The aim is to create a new instance of explorer.exe, which will launch CompMgmtLauncher. | Once the bas64 is deobfuscated, a dll is obtained, which is responsible for bypassing the UAC seen in the dynamic section in the previous point.
REvil has used PowerShell to delete volume shadow copies and download files.
By targeting virtual machines, ransomware operators can also encrypt multiple servers at once with a single command. In June, researchers spotted a new REvil ransomware Linux encryptor designed to target VMware ESXi virtual machines, a popular enterprise virtual machine platform.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
By targeting virtual machines, ransomware operators can also encrypt multiple servers at once with a single command. In June, researchers spotted a new REvil ransomware Linux encryptor designed to target VMware ESXi virtual machines, a popular enterprise virtual machine platform.
“gegevens stelen” en in het voorbeeld: “10GB data naar server in Finland.”
Sodinokibi operators may steal data in advance and then resort to extortion tactics that exceed the ability of the malware itself. | Those who refuse to pay up, relying on their ability to recover data, will then receive threats to have that data exposed on an auction site the group calls The Happy Blog.
As evidence, the Sodin hackers have posted documents on the Dark web purporting to be from the victims including company computer file directories, partial customer lists, customer quotes, copies of contracts, and even what appears to be several official IDs.
253 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware group/family discussed as the central case study, tied to criminal investigation and court proceedings in Russia. The content frames it as a double-extortion ransomware operation involving data encryption and threats to leak stolen data.
Known ransomware family whose code reportedly shared similarities with the Ransom Cartel encryptor.
Ransomware family used in the Kaseya supply-chain-style attack to distribute a malicious payload via vulnerable VSA servers, encrypt downstream victim systems, and demand ransom. The content also describes REvil as a prolific ransomware gang/toolset that targeted MSPs and their customers at scale.
REvil/Sodinokibi is mentioned only as comparative background about other ransomware operations that were disrupted.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.