Ransomware operators behind REvil/Sodinokibi and DoppelPaymer increasingly ran intrusions like targeted espionage campaigns, combining long dwell times, privilege escalation, lateral movement, data theft, and enterprise-wide encryption. Research from Mandiant, Secureworks, JPCERT/JSAC, and CERT-FR describes attackers gaining entry through exposed RDP and VPN services, phishing-delivered malware such as QAKBOT, Emotet, and Dridex, brute force, and exploitation of internet-facing systems, then expanding control with tools including Mimikatz, BloodHound, PsExec, WMI, Cobalt Strike, and Empire. In many cases, affiliates or partner crews obtained domain administrator access, tampered with backups and security tools, abused Active Directory group policy and scheduled tasks, and used open SMB shares or administrative utilities to push ransomware across networks.
REvil also helped normalize double extortion by stealing data before encryption, threatening public leaks, and in some cases publishing victim files or warning that stolen information could be sold or used to pressure public companies through market disclosure. Reporting on Sodinokibi showed the gang first releasing allegedly stolen victim data after nonpayment and later promoting leak-site tactics as a standard coercion method, while Sophos observed exfiltration in roughly half of investigated REvil incidents, often staging data in Mega.nz. Separate reporting said REvil’s operators secretly retained a master decryption capability and allegedly hijacked affiliate negotiations, underscoring how ransomware-as-a-service groups maintained centralized control even as affiliates conducted the intrusions.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
21 events from the most recent confirmed update back to the earliest known activity.
BleepingComputer reported that REvil developers had allegedly embedded a cryptographic backdoor enabling them to decrypt any victim system and secretly hijack ransom negotiations from affiliates.
In early July 2021, Fabian Wosar explained that REvil samples contained a hardcoded operator/master public key, allowing operators holding the corresponding private key to recover system private keys and decrypt any victim machine.
At Japan Security Analyst Conference 2020, Secureworks presented research arguing that targeted ransomware attacks increasingly resembled intrusions using post-compromise techniques such as privilege escalation, lateral movement, and AD-based deployment.
The 2021 BleepingComputer report says underground discussions alleging that REvil operators scammed affiliates by taking over negotiations had circulated since at least 2020.
FireEye/Mandiant presented research on how ransomware operations had matured in 2020, focusing on REvil’s affiliate model and the QAKBOT-to-DoppelPaymer partnership model.
The Mandiant whitepaper says it responded during 2020 to DoppelPaymer deployments in Europe and globally where initial access originated from QAKBOT infections and was later handed to ransomware operators.
The Mandiant Black Hat presentation states that QAKBOT campaigns in early 2020 used unsophisticated phishing for initial compromise and later enabled ransomware developers to access victim environments.
Sodinokibi/REvil published approximately 337MB of allegedly stolen files said to belong to Artech Information Systems after a ransom was not paid on time, marking the group’s first public data leak.
ANSSI stated that BitPaymer victims were compromised through phishing campaigns in July 2019, adding to other known initial access vectors such as weak RDP and compromised websites.
ANSSI said Morphisec published a YARA rule in July 2019 to detect BitPaymer’s custom packer, and ANSSI confirmed it detected the ransomware’s obfuscation layer.
ANSSI reported that CrowdStrike detected a new BitPaymer variant called DoppelPaymer in July 2019 and assessed it might reflect a split within the BitPaymer development team.
The Mandiant Black Hat materials state that REvil, also known as Sodinokibi, was first seen in May 2019 and operated as a ransomware-as-a-service platform.
The Mandiant whitepaper says the actor behind the REvil platform began advertising for affiliates in mid-2019, formalizing its ransomware-as-a-service model.
The Secureworks presentation says ransomware incidents evolved from mail attachments and drive-by downloads to manually operated attacks against corporate networks beginning around 2018.
ANSSI highlighted a notable BitPaymer incident in which multiple Scottish hospitals were compromised.
ANSSI reported that BitPaymer, also known as FriedEx or IEncrypt, has been used since at least July 2017 in manually operated ransomware attacks against private and public organizations.
The Secureworks JSAC 2020 presentation states that WannaCry caused large-scale incidents in 2017 by exploiting public-facing servers vulnerable to MS17-010.
Bitdefender released a universal REvil decryption tool that worked for victims encrypted up to July 13, 2021; the article says it relied on the same master-key capability built into REvil’s cryptographic design.
As part of its forum announcement, REvil linked to a 10MB sample of allegedly stolen financial and tax data from an unnamed victim and threatened to release more if payment was not made.
A public-facing REvil representative known as Unknown said the group had finished a blog for publishing stolen data from non-paying victims and discussed escalating pressure, including possible notifications to stock exchanges such as NASDAQ.
BleepingComputer reported that REvil operators started telling affiliates to copy victim data before encrypting systems so it could be used for extortion on a new leak site.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
news.sophos.com
Open sourcebleepingcomputer.com
Open sourcebleepingcomputer.com
Open sourcebleepingcomputer.com
Open sourcei.blackhat.com
Open sourcei.blackhat.com
Open sourcejsac.jpcert.or.jp
Open sourcecert.ssi.gouv.fr
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.