Reveton ransomware spread through drive-by downloads, compromised websites, malvertising, spam, fake software downloads, and secondary delivery by existing botnets, while posing as law-enforcement agencies such as the FBI to demand fraudulent fines for alleged child pornography or piracy violations. Reporting on the operation said the malware was frequently delivered via exploit kits including BlackHole, often alongside the Citadel banking Trojan, and that some variants also stole stored passwords in addition to locking victims' systems.
The campaign relied on a broader criminal ecosystem built to maximize infections and evade disruption, including traffers, redirectors, reverse proxies, traffic direction systems, fake websites, domain rotation, fast-flux hosting, DGAs, crypting services, AV-check services, and underground advertising platforms. Researchers and law enforcement described the scheme as highly profitable, generating tens of thousands of euros per day across multiple countries, and warned that remediation often required full system reinstallation because the visible ransomware screen could mask additional malware on the infected host.

TTPs, infrastructure, and targeting history in one profile.
7 events from the most recent confirmed update back to the earliest known activity.
A second statistics page cited by researchers showed the attackers earned €43,750 on the day after May 17, 2012. The data illustrated rapid day-to-day revenue from the ransomware campaign.
Statistics from a ransomware operation showed that 322 victims across all targeted countries paid on May 17, 2012, generating more than €28,000 for the attackers. The figures were cited as evidence of the profitability of Reveton-style police-themed ransomware scams.
Analysis of the ransomware ecosystem described how compromised sites, malvertising, spam, fake downloads, and botnet tasking were used to feed victims into redirectors, traffic direction systems, and exploit kits such as Blackhole, Redkit, and Cool. The piece also documented supporting criminal services including crypting, AV-checking, domain rotation, and traffic brokering.
The analysis noted that a new infection vector appeared in early 2013 in which attackers brute-forced Remote Desktop Protocol access to Windows servers and then deployed crypto-ransomware. This marked an expansion beyond web- and botnet-driven delivery methods.
The Reveton ransomware scams had previously targeted European users before the wave that spoofed FBI notices in the United States. The campaign localized fake law-enforcement messages based on victims' countries.
Researchers gained access to one of the three main BlackHole exploit panels used by a Reveton malware gang. The panel showed more than 187,000 potential victims in a single day and over 11,000 successful Reveton infections, with outdated Java as the leading infection vector.
The FBI warned that online extortion scams impersonating the FBI had surged, with victims' computers locked until a fake fine was paid. The Internet Crime Complaint Center said it was inundated with complaints tied to the campaign.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.