Sodinokibi, also known as REvil and BlueCrab, was distributed through multiple intrusion paths while its operators and affiliates steadily refined payload delivery and defense evasion. Researchers documented infections delivered via malspam, spear-phishing, compromised websites, exposed or stolen RDP access, and exploitation of vulnerabilities including CVE-2019-2725, CVE-2018-13379, and CVE-2019-11510. In South Korea, attackers also abused vulnerable WordPress sites for SEO poisoning, planting fake forum pages that pushed victims to download ZIP archives containing malicious JavaScript, which then fetched additional scripts, launched PowerShell, loaded a .NET injector in memory, and executed the ransomware through a Delphi-based loader.
The operation paired technical sophistication with aggressive monetization. Analysts reported frequent changes to JavaScript obfuscation, command-and-control paths, PowerShell execution methods, process injection techniques, and target process names to reduce antivirus detection, alongside logic to disable security tooling and delete Volume Shadow Copies before encryption. IBM described the group’s use of Curve25519, ECDH, Salsa20, AES, and SHA-3 in its encryption workflow, as well as its double-extortion model of stealing data and threatening publication on The Happy Blog. The ransomware was linked to a broad affiliate ecosystem, represented 22% of IBM X-Force incident response engagements in 2020, and was reported to heavily impact organizations in the United States, United Kingdom, Australia, and Canada.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
Beginning on 2020-12-15, AhnLab observed the JavaScript stage add randomized line ordering for each download and switch identifier naming from random strings to English words such as "apple" to evade detection.
AhnLab reported that the malware removed registry autorun registration and had wscript.exe execute the environment-variable command directly. It also changed the PHP endpoint name used by C2 from /check.php to /search.php.
On the same date, AhnLab observed the .NET injector change how it stored the Delphi loader, moving from reversed Base64 encoding to string substitution markers such as "!@#" and later "$%^".
AhnLab observed a BlueCrab/Sodinokibi variant that stopped dropping the PowerShell script to disk and instead stored the .NET injector in the registry for PowerShell to load from there. The same variant also registered the PowerShell command in an environment variable and a Run key for post-reboot execution.
AhnLab observed the BlueCrab/Sodinokibi campaign change its command-and-control communications from HTTP to HTTPS. This marked an infrastructure change in the malware's delivery chain.
IBM said Sodinokibi accounted for 22% of its X-Force incident response engagements during 2020, reflecting the group's prominence in ransomware activity that year.
IBM reported that in 2020 the ransomware's operators deposited USD 1 million in Bitcoin on a Russian-speaking cybercrime forum as part of a drive to recruit more affiliates.
Trend Micro reported that the Sodinokibi ransomware family was first detected in April 2019 and linked to the retired GandCrab ransomware.
3 references tracked. Mallory keeps watching after this page renders.
securityintelligence.com
Open sourceasec.ahnlab.com
Open sourcetrendmicro.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.