REvil, also known as Sodinokibi, abruptly lost its public-facing and backend infrastructure, with its Tor leak and payment sites, clear-web presence, and the decoder[.]re domain all going offline at roughly the same time. The disappearance was highly unusual for a group whose infrastructure had been comparatively stable, and it followed REvil’s involvement in several high-profile ransomware incidents, including attacks on Kaseya and JBS Foods.
The outage came amid intense law-enforcement and geopolitical pressure after the Kaseya VSA supply-chain attack, which reportedly impacted about 60 managed service providers and more than 1,500 businesses. Reporting cited several possible explanations, including a government takedown, a legal demand that prompted operators to wipe servers, a voluntary shutdown, technical failure, or a rebranding effort, but no definitive cause was confirmed; researchers also warned that even a successful disruption would not necessarily end the threat, as affiliates could regroup or reappear under a new name.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
By October 2021, users visiting REvil's Happy Blog saw a default Fedora nginx 404 page instead of the gang's normal content, indicating the onion services may have been compromised rather than simply offline. REvil spokesperson 0_neday claimed on XSS that attackers used private Tor service keys belonging to former representative UNKN/Unknown to redirect the hidden service.
Starting overnight and observed by early July 13, REvil's dark web, clear web, and backend infrastructure became inaccessible, including its Tor sites and decoder[.]re domain. Analysts described the simultaneous outage as unusual and said the cause was unconfirmed.
On July 2, REvil exploited a zero-day vulnerability in Kaseya VSA remote management software to attack about 60 managed service providers. The campaign went on to affect more than 1,500 businesses and drew major law-enforcement attention.
During the outage, the XSS Russian-speaking hacking forum banned REvil's public-facing representative, 'Unknown.' Reporting also cited unconfirmed forum rumors that REvil may have erased its servers after learning of a government legal request or subpoena.
Following the Kaseya incident, reporting noted that REvil had recently added Kaseya and many of its managed service provider customers to its list of victims. The group was also linked in the coverage to earlier attacks including JBS Foods.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
darkowl.com
Open sourcethreatpost.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.