REvil, also known as Sodinokibi and tracked by some researchers as GOLD SOUTHFIELD, evolved into one of the most consequential ransomware-as-a-service operations by combining aggressive affiliate-driven intrusions with increasingly sophisticated extortion. Reporting tied the group to multiple access methods including RDP brute force, spam, watering-hole compromises, malvertising, unpatched VPN and RDP systems, and malware such as IcedID and Qakbot. Researchers also documented how REvil’s malware and ecosystem were reused or repurposed: Secureworks assessed that LV ransomware was a modified REvil 2.03 beta with a replaced configuration, while separate reporting linked REvil’s rise to the vacuum left by GandCrab and described its shift toward leak-site pressure, targeted credential fields, affiliate tracking, and removal of geographic execution restrictions in later samples.
The operation’s most damaging campaign exploited multiple zero-day vulnerabilities in Kaseya VSA, abusing the platform’s auto-update mechanism to push ransomware through managed service providers and impact an estimated 1,500 downstream organizations. Victims included Swedish retailers and dozens of customers served by affected MSPs, prompting Kaseya to shut down SaaS VSA, advise customers to take internet-exposed on-premises servers offline, and work with the FBI. After law-enforcement disruption and arrests, researchers reported revived REvil Tor infrastructure and newly compiled samples in 2022 that appeared to come from source code rather than recycled binaries, with updated keys, payment domains, victim-specific account targeting, and evidence of active development despite one buggy build that renamed files without encrypting them.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
33 events from the most recent confirmed update back to the earliest known activity.
On February 1, 2022, Bitdefender announced a free universal decryptor for REvil/Sodinokibi ransomware, developed with a trusted law enforcement partner. The tool was released before the investigation concluded to help victims recover files encrypted in attacks that occurred before July 13, 2021.
Secureworks noted that an October 2021 REvil sample had removed the malware's prohibited-region protections. This change allowed execution regardless of the victim system's geography.
Secureworks says GOLD SOUTHFIELD infrastructure had been shuttered since October 2021, and BleepingComputer reports REvil shut down in October after a law enforcement operation hijacked its Tor servers. This marked a major disruption to the operation.
Secureworks observed REvil's payment and leak sites responding again on September 7, 2021, and identified a newly compiled REvil sample on September 9. The researchers assessed GOLD SOUTHFIELD had restored and modified an older 2.06 codebase backup while removing features such as CIS-region checks, C2 logic, and clearnet payment domains.
As the July 2, 2021 attack unfolded, Kaseya shut down its SaaS VSA service and warned customers to immediately take internet-exposed on-premises VSA servers offline. The response aimed to stop further ransomware propagation.
On July 2, 2021, REvil exploited zero-day vulnerabilities in Kaseya VSA and pushed a malicious payload masquerading as an agent update. The supply-chain attack spread through managed service providers to downstream customers.
Following the Kaseya incident, REvil claimed on its leak site that more than one million systems had been encrypted and demanded $70 million in Bitcoin for a universal decryptor. The demand became one of the most prominent ransom asks of the campaign.
Kaseya reported that up to 60 managed service providers and as many as 1,500 client organizations were affected by the REvil campaign. Separate reporting says at least 50 MSPs had vulnerable VSA instances exploited, with major disruption including Swedish retailers and pharmacies.
Dutch disclosure group DIVD reported about seven Kaseya VSA vulnerabilities to Kaseya in April 2021, including a critical authentication bypass and SQL injection issues. Kaseya fixed some flaws before July 2021, but not all of them.
Secureworks concluded that GOLD NORTHFIELD had repurposed a REvil binary to create LV ransomware by replacing its configuration and CRC32 integrity values. The researchers assessed the modified malware was based on a REvil 2.03 beta binary.
REvil launched its Happy Blog leak and extortion site in February 2020. The site accelerated the group's use of data theft and public shaming to pressure victims.
Trend Micro states that Clop adopted double extortion in 2020 and publicized data stolen from a pharmaceutical company. This marked Clop's shift to leak-based coercion.
Trend Micro says SunCrypt and RagnarLocker were early adopters of triple extortion in the latter half of 2020. This added DDoS pressure to encryption and data-leak threats.
A newer SunCrypt variant written in C/C++ was discovered in mid-2020. Researchers noted it did not share code with the earlier 2019 Go-based SunCrypt sample, despite similar ransom-note structure and wording.
Researchers traced SunCrypt activity back to approximately October 2019 and identified a Go-based Windows sample from that period. The report characterizes this 2019 variant as a likely beta release.
The REvil representative known as UNKN recruited the operation's first affiliate in July 2019. This marks an early operational milestone in REvil's ransomware-as-a-service model.
QNAPCrypt, also known as eCh0raix, was used against QNAP and Synology NAS devices in July 2019. Later research used these 2019 samples to compare code overlap with SunCrypt.
On June 19, 2019, a watering-hole compromise of winrar.it in Italy delivered Sodinokibi instead of the legitimate WinRAR installer. The incident showed the ransomware being spread through a compromised trusted site.
The Italian report documented Sodinokibi infections delivered through malvertising on June 7, 2019. This was one of several propagation methods observed locally.
Affiliates distributed Sodinokibi through spam campaigns observed in June 2019, including a Booking.com-themed lure. The report identifies spam as an active delivery channel during that month.
Multiple sources state GandCrab retired in early June 2019, after which Sodinokibi/REvil emerged as a likely successor in the ransomware-as-a-service ecosystem. This transition is presented as a key backdrop for REvil's rise.
Researchers recorded the first Italian Sodinokibi case on May 24, 2019, attributing it to an RDP brute-force intrusion. The report says this was the first observation of the ransomware in Italy.
When first discovered in April 2019, REvil was being delivered by exploiting vulnerabilities in Oracle WebLogic servers. This is described as one of the earliest observed deployment methods for the malware.
Maze introduced the double-extortion model in late 2019 by pairing file encryption with threats to leak stolen data. Later ransomware families adopted this approach widely.
Intezer concluded that SunCrypt and QNAPCrypt shared highly distinctive code, including a unique 'EncEAS' typo and nearly identical encryption logic, indicating shared source code or a common author. The report also assessed that the two ransomware families were likely operated by different threat actors.
BankInfoSecurity reports that law enforcement later obtained a universal decryption key for systems encrypted in the Kaseya REvil campaign. The key's release was delayed for several weeks to avoid disrupting an ongoing investigation.
BleepingComputer reported that REvil had returned with revived Tor infrastructure and a newly compiled encryptor tied directly to REvil source code. Researchers cited in the article said the sample was compiled from source rather than patched from older binaries.
Twitter user @JakubKroustek detected the April 2022 REvil sample on April 29, 2022. The discovery helped confirm that new REvil-linked malware was circulating again.
An April 2022 REvil sample carried a compile timestamp of 2022-04-26 19:39:04 and was nearly identical to the March sample, but contained a bug that renamed files without encrypting them. The sample still indicated ongoing development of the malware.
The March 2022 sample's ransom note referenced new Tor domains that became active on April 19, 2022, when GOLD SOUTHFIELD infrastructure resumed activity. This provided a concrete infrastructure indicator of the group's return.
REvil-linked infrastructure resumed activity in April 2022 after being offline since October 2021. Secureworks tied the resumed activity to new samples and renewed leak-site operations.
A REvil sample dated March 22, 2022 contained multiple code and configuration changes, including a new '-t' argument, updated public keys, GUID-based affiliate tracking, and victim-specific 'accs' credentials. Secureworks assessed the developer had access to REvil source code and that the malware was under active development.
Secureworks said the LV sample's characteristics aligned with REvil 2.02 samples first identified in the wild on June 17, 2020. This anchored the repurposed LV binary to a contemporaneous REvil code branch.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
15 references tracked. Mallory keeps watching after this page renders.
bankinfosecurity.com
Open sourceintezer.com
Open sourcetrendmicro.com
Open sourcesecureworks.com
Open sourcesecureworks.com
Open sourcetgsoft.it
Open sourcegdatasoftware.com
Open sourcegroup-ib.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.