🔴 [LATEST] 313 TEAM TARGETS AL RAJHI BANK AND SAUDI CIVIL DEFENSE, SITES UNREACHABLE FROM DOZENS OF LOCATIONS    ◆    🔴 [LATEST] DDOS QATAR INVESTMENT AUTHORITY: 1 CRITICAL SOVEREIGN WEB PORTAL DOWN    ◆    🔴 [LATEST] RIPPERSEC TARGETS ISRAEL CART: 1 CRITICAL E-COMMERCE PLATFORM DISRUPTED    ◆    🔴 [LATEST] US NAVY DDOS ATTACK: 3 CRITICAL MILITARY PORTALS DISRUPTED    ◆    🔴 [LATEST] QATAR LIVING DDOS ATTACK: 1 CRITICAL EXPATRIATE PORTAL DISRUPTED

> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE

Flag
REVIL (SODINOKIBI)

/actor/revil-sodinokibi/  ·  0 intel reports

Year Established
2019
Attribution
Russia
Motivation
Financial
Modus Operandi (MO)
RaaS, supply chain attacks, auctioning stolen data, record-breaking ransom demands
Primary Aliases
Sodinokibi, GandCrab successor, GOLD SOUTHFIELD

REvil (also known as Sodinokibi) was one of the most technically sophisticated and financially successful ransomware operations in history, widely assessed to be operated by Russian-speaking cybercriminals with tacit protection from Russian state authorities. Active from 2019 until its eventual disruption in late 2021, REvil is estimated to have extorted hundreds of millions of dollars from thousands of victims globally and pioneered several techniques that became industry standards across the ransomware ecosystem.

REvil's most audacious operations include the May 2021 attack on JBS Foods , the world's largest meat processing company , causing the shutdown of beef processing plants across the United States, Australia, and Canada and disrupting global food supply chains, resulting in a $11 million ransom payment. In July 2021, REvil executed the largest ransomware supply chain attack in history: exploiting a zero-day vulnerability in Kaseya VSA remote monitoring software to simultaneously encrypt systems at approximately 1,500 managed service provider clients globally, demanding a $70 million ransom for a universal decryptor.

REvil pioneered the "auctioning" of stolen data on dark web sites , selling victim data to competitors rather than simply publishing it , and introduced a Linux/ESXi-targeting encryptor to attack virtual machine infrastructure, both innovations subsequently adopted by other ransomware groups. The group's RaaS infrastructure was technically sophisticated and offered affiliates an 80/20 revenue split.

Following significant law enforcement pressure, REvil's infrastructure went offline in July 2021 after the Kaseya attack. US and international law enforcement subsequently arrested multiple REvil affiliates, including a Ukrainian national responsible for the Kaseya attack who was extradited to the United States and sentenced to over 13 years in federal prison.

Threat Mitigation and Strategic Hardening: Network defense against campaigns linked to REvil (Sodinokibi) requires continuous threat surface management, dark web monitoring for stolen employee credentials, and automated telemetry correlation. Organizations should reference our Cyber Risk Checker and report critical indicators via Secure Drop.

STATUS: ACTIVE CLASSIFICATION: RANSOMWARE SYNDICATE LAST SEEN: Unknown

> LINKED_INTEL_REPORTS (0)

[NULL] No intel reports found for this actor.

> cd ../articles