REvil, also known as Sodinokibi or Sodin, is a ransomware-as-a-service operation first observed in 2019. It emerged as a major financially motivated ransomware family targeting private companies, government entities, schools, hospitals, and other organizations worldwide, with reporting linking it to more than 1,000 victims during its peak activity period from 2019 to 2021. REvil has been associated with high-profile supply-chain and managed service provider compromise activity, including abuse of Kaseya VSA, and early deployments also exploited Oracle WebLogic vulnerability CVE-2019-2725. The operation has been discussed in connection with Russian-speaking cybercriminal ecosystems and former members have been referenced in later ransomware activity.
Technically, REvil is a highly configurable Windows ransomware family operated through an affiliate model in which core operators maintain the malware and payment infrastructure while affiliates conduct intrusions and deploy the encryptor. It stores encrypted JSON configuration data, decrypts strings at runtime, dynamically resolves imports, and can communicate with controllers over HTTPS when configured to do so. The malware includes logic to avoid infecting systems associated with certain languages and keyboard layouts, particularly across Russia, the CIS, and nearby regions, terminating execution when exclusion conditions are met.
Before encryption, REvil can query and modify the Windows Registry to store encryption parameters, victim key material, and system information. Earlier versions also used the Registry for persistence, though that mechanism was later removed. The malware can attempt privilege escalation, including historical use of CVE-2018-8453 and repeated elevation prompts. It also prepares systems for encryption by terminating selected processes, stopping or deleting services associated with backups, databases, mail, and security tooling, and deleting shadow copies to inhibit recovery.
REvil encrypts files on local and network-accessible storage, appends a generated extension to encrypted files, drops ransom notes, and changes the desktop background. Delivery has been observed through exploitation of public-facing applications, malicious email attachments such as weaponized Word documents, and DLL sideloading using a legitimate Windows Defender component to load a malicious library. REvil payloads have also been delivered through Gootloader campaigns that relied on SEO poisoning and compromised websites. The family is widely recognized as one of the defining ransomware operations of the late 2010s and early 2020s.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
REvil ransomware exploits a kernel privilege escalation vulnerability in win32k.sys tracked as CVE-2018-8453 to gain SYSTEM privileges on the infected host. | REvil aka Sodinokibi, Sodin is a ransomware family operated as a ransomware-as-a-service (RaaS). Deployments of REvil first were observed in April 2019, where attackers leveraged a vulnerability in Oracle WebLogic servers tracked as CVE-2019-2725.
Deployments of REvil first were observed in April 2019, where attackers leveraged a vulnerability in Oracle WebLogic servers tracked as CVE-2019-2725. | REvil aka Sodinokibi, Sodin is a ransomware family operated as a ransomware-as-a-service (RaaS). Deployments of REvil first were observed in April 2019, where attackers leveraged a vulnerability in Oracle WebLogic servers tracked as CVE-2019-2725.
Previously, Pulse Connect Secure has been targeted by a variety of threat actors including ransomware groups and other nation-state aligned threat actors over the last five years: CVE-2019-11510 Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability. | We’ve also published several blog posts about vulnerabilities in Pulse Connect Secure: ... CVE-2019-11510: Critical Pulse Connect Secure Vulnerability Used in Sodinokibi Ransomware Attacks
The 2021 Kaseya VSA compromise by REvil used several zero-day vulnerabilities, including CVE-2021-30116 and CVE-2021-30120, which allowed them to bypass authentication requirements to access VSA servers en route to deploying ransomware in up to 1500 downstream client networks. | In early 2021, Quanta Computer, a Taiwanese technology manufacturer and Apple partner, was compromised by the REvil ransomware group... The 2021 Kaseya VSA compromise by REvil used several zero-day vulnerabilities, including CVE-2021-30116 and CVE-2021-30120, which allowed them to bypass authentication requirements to access VSA servers en route to deploying ransomware in up to 1500 downstream client networks.
In early 2021, Quanta Computer, a Taiwanese technology manufacturer and Apple partner, was compromised by the REvil ransomware group... The 2021 Kaseya VSA compromise by REvil used several zero-day vulnerabilities, including CVE-2021-30116 and CVE-2021-30120, which allowed them to bypass authentication requirements to access VSA servers en route to deploying ransomware in up to 1500 downstream client networks. | The 2021 Kaseya VSA compromise by REvil used several zero-day vulnerabilities, including CVE-2021-30116 and CVE-2021-30120, which allowed them to bypass authentication requirements to access VSA servers en route to deploying ransomware in up to 1500 downstream client networks.
Computer giant Acer has been hit by a REvil ransomware attack where the threat actors are demanding the largest known ransom to date, $50,000,000.
10 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
REvil aka Sodinokibi, Sodin is a ransomware family operated as a ransomware-as-a-service (RaaS). Deployments of REvil first were observed in April 2019, where attackers leveraged a vulnerability in Oracle WebLogic servers tracked as CVE-2019-2725.
In 2023, FIN7 expanded its operations to include the deployment of ransomware through affiliations with RaaS groups such as REvil and Maze, while also managing its own RaaS programs, including the now-retired Darkside and BlackMatter.
In 2020 ELBRUS transitioned from using PoS malware to deploying ransomware as part of a financially motivated extortion scheme, specifically deploying the MAZE and Revil RaaS families.
One group known for pivoting is Evil Corp., the gang behind Revil. Revil’s tactics align with why a threat group would target an insurance provider.
In 2020 ELBRUS transitioned from using PoS malware to deploying ransomware as part of a financially motivated extortion scheme, specifically deploying the MAZE and Revil RaaS families.
UNC2628 is thought to partner with other RaaS services including REvil and Netwalker.
35 distinct techniques documented for this family, organized by ATT&CK tactic.
Once the code was in place, a task named “RanCommand” was performed, effectively starting the Sodinokibi encryption process across the network.
Windows versions 5.2 and later, under PowerShell: Get-WmiObject Win32_Shadowcopy | ForEach-Object {$_.Delete();}
Windows versions 5.1 and earlier: cmd.exe /c vssadmin.exe Delete Shadows /All /Quiet & bcdedit /set {default} recoveryenabled No & bcdedit /set {default} bootstatuspolicy ignoreallfailures
Sandworm Team leveraged Microsoft Office attachments which contained malicious macros that were automatically executed once the user permitted them... APT29 has used various forms of spearphishing attempting to get a user to open attachments... DarkGate is distributed through phishing links to VBS or MSI objects requiring user interaction for execution.
Once the code was in place, a task named “RanCommand” was performed, effectively starting the Sodinokibi encryption process across the network.
Tetra was able to confirm that the “Tech Support” account, and all its administrative-level privileges, was compromised. This single user gave the threat actor full access to the network.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
Once the code was in place, a task named “RanCommand” was performed, effectively starting the Sodinokibi encryption process across the network.
It then performs a process hollowing on that executable to load the Delphi component.
REvil ransomware exploits a kernel privilege escalation vulnerability in win32k.sys tracked as CVE-2018-8453 to gain SYSTEM privileges on the infected host.
Tetra was able to confirm that the “Tech Support” account, and all its administrative-level privileges, was compromised. This single user gave the threat actor full access to the network.
REvil ransomware incorporates techniques to make the task of static analysis more difficult for an analyst. Most of the strings used during execution are decrypted at runtime only when needed.
The behavior of the following samples was analyzed for this report: Sample SHA256 REvil packed ... REvil not packed ...
During its initialization phase, REvil starts by dynamically resolving the imports it needs to function correctly... each value is decoded and resolved to the correct API... additional APIs are resolved by their names with the help of the GetProcAddress API.
It then performs a process hollowing on that executable to load the Delphi component.
Finally, REvil ransomware marks its binary code for deletion during the next reboot and terminates execution.
Tetra was able to confirm that the “Tech Support” account, and all its administrative-level privileges, was compromised. This single user gave the threat actor full access to the network.
The content repeatedly describes malware and threat actors decoding, decrypting, deobfuscating, or unpacking payloads, strings, configuration data, commands, and C2 responses prior to execution or use.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
Then it will terminate all processes with names that match the elements of the prc JSON array...
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
For the check to succeed and REvil to exit, both a whitelisted system language and a whitelisted keyboard layout must be present. Otherwise, the ransomware continues its execution normally.
Avaddon checks for specific keyboard layouts and OS languages to avoid targeting Commonwealth of Independent States (CIS) entities... Bazar can perform a check to ensure that the operating system's keyboard and language settings are not set to Russian... Clop has checked the keyboard language using the GetKeyboardLayout() function... Ryuk has been observed to query the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\Language and the value InstallLanguage.
Exfiltrates encrypted information on the infected host to remote controllers.
On top of client applications such as those provided by Mega, many ransomware families may use other software or built-in operating system utilities to exfiltrate data. We’ll use Mega as the example here... you can look for execution of any process that is not chrome.exe ... initiating a network connection to the domains mega.io or mega.co.nz .
The U.S. is seeking an individual with the same name who is a suspect in REvil ransomware attacks.
First, it will try to stop and delete services if the names match one of the regular expressions in the svc JSON configuration list... | Then it will terminate all processes with names that match the elements of the prc JSON array, for instance: "prc":[ "w3wp", "thunderbird", "mydesktopqos", "powerpnt", "outlook" ... ]
Finally REvil will delete the volume shadow copies. The way this is accomplished depends on the Windows version: Windows versions 5.1 and earlier: cmd.exe /c vssadmin.exe Delete Shadows /All /Quiet & bcdedit /set {default} recoveryenabled No & bcdedit /set {default} bootstatuspolicy ignoreallfailures Windows versions 5.2 and later, under PowerShell: Get-WmiObject Win32_Shadowcopy | ForEach-Object {$_.Delete();}
17 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware family/group associated with attacks conducted between April 2019 and July 2021, impacting over 1,000 entities including private companies, government offices, schools, and hospitals.
Ransomware operation linked in the article to widespread attacks against more than 1,000 victims across private companies, law enforcement, government offices, schools, and hospitals.
Ransomware family cited as an example of Russian law-enforcement action against cybercriminal operators.
A ransomware family listed among classes with sparse training data in the evaluation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.