REvil, also known as Sodinokibi and BlueCrab, is a Windows ransomware family associated with financially motivated intrusion activity and broad affiliate-based distribution. It has been actively distributed against users in South Korea and has also appeared as a downstream payload in larger malware delivery ecosystems such as Gootloader campaigns. The malware is commonly delivered through SEO-poisoned fake forum pages hosted on compromised websites, where victims are lured into downloading archive files containing malicious JavaScript. In some campaigns, the JavaScript stage selectively delivers different follow-on payloads depending on whether the victim appears to be part of an Active Directory domain environment, with enterprise victims receiving Cobalt Strike instead of the ransomware payload.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
PowerShell 스크립트는 .NET 언어로 된 Injector를 메모리에 로드하여 실행하고 Injector는 Delphi 언어로 된 랜섬웨어 Loader를 정상 프로세스에 인젝션하여 실행한다.
2020년 10월 12일 확인된 변형에서는 별도의 프로세스를 Suspend 상태로 생성한 뒤 Delphi Loader의 프로세스 메모리 구조를 인젝션 후 Resume하는 전형적인 Process Hollowing 방식으로 변형되었다.
내부 코드는 난독화 되어 있으며... 1~2일 내에 의미 없는 쓰레기 코드를 추가하거나 동일 기능의 다른 문법을 사용하는 등의 간단한 변형으로 진단을 우회한다.
PowerShell 스크립트는 .NET 언어로 된 Injector를 메모리에 로드하여 실행하고 Injector는 Delphi 언어로 된 랜섬웨어 Loader를 정상 프로세스에 인젝션하여 실행한다.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
BlueCrab is only mentioned as part of an AhnLab detection signature list and is not described as part of the analyzed infection chain.
Named as one of the final payloads delivered by the Gootloader ecosystem, mostly targeting Korean users.
JS-distributed ransomware that normally delivers the BlueCrab/REvil payload, but in enterprise Active Directory environments it checks %USERDNSDOMAIN% and instead delivers Cobalt Strike for follow-on intrusion activity.
BlueCrab is a ransomware family distributed via SEO-poisoned fake forum pages. Victims download a ZIP containing a malicious JavaScript file, which retrieves additional JavaScript from C2, launches PowerShell, loads a .NET injector, injects a Delphi loader, and ultimately executes the BlueCrab ransomware payload to delete VSCs and encrypt files. The campaign frequently changes obfuscation, C2 paths, execution chains, and injection targets to evade AV detection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.