{"id":445,"count":0,"description":"<div class=\"actor-dossier\" style=\"display:flex;flex-wrap:wrap;gap:12px;margin-bottom:20px\">\n  <div style=\"flex:1;min-width:160px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Year Established<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">2019<\/div>\n  <\/div>\n  <div style=\"flex:1;min-width:160px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Attribution<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Russia<\/div>\n  <\/div>\n  <div style=\"flex:1;min-width:160px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Motivation<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Financial<\/div>\n  <\/div>\n  <div style=\"flex:2;min-width:200px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Modus Operandi (MO)<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">RaaS, supply chain attacks, auctioning stolen data, record-breaking ransom demands<\/div>\n  <\/div>\n  <div style=\"flex:2;min-width:200px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Primary Aliases<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Sodinokibi, GandCrab successor, GOLD SOUTHFIELD<\/div>\n  <\/div>\n<\/div>\n<p>REvil (also known as Sodinokibi) was one of the most technically sophisticated and financially successful ransomware operations in history, widely assessed to be operated by Russian-speaking cybercriminals with tacit protection from Russian state authorities. Active from 2019 until its eventual disruption in late 2021, REvil is estimated to have extorted hundreds of millions of dollars from thousands of victims globally and pioneered several techniques that became industry standards across the ransomware ecosystem.<\/p>\n<p>REvil's most audacious operations include the May 2021 attack on JBS Foods ,  the world's largest meat processing company ,  causing the shutdown of beef processing plants across the United States, Australia, and Canada and disrupting global food supply chains, resulting in a $11 million ransom payment. In July 2021, REvil executed the largest ransomware supply chain attack in history: exploiting a zero-day vulnerability in Kaseya VSA remote monitoring software to simultaneously encrypt systems at approximately 1,500 managed service provider clients globally, demanding a $70 million ransom for a universal decryptor.<\/p>\n<p>REvil pioneered the \"auctioning\" of stolen data on dark web sites ,  selling victim data to competitors rather than simply publishing it ,  and introduced a Linux\/ESXi-targeting encryptor to attack virtual machine infrastructure, both innovations subsequently adopted by other ransomware groups. The group's RaaS infrastructure was technically sophisticated and offered affiliates an 80\/20 revenue split.<\/p>\n<p>Following significant law enforcement pressure, REvil's infrastructure went offline in July 2021 after the Kaseya attack. US and international law enforcement subsequently arrested multiple REvil affiliates, including a Ukrainian national responsible for the Kaseya attack who was extradited to the United States and sentenced to over 13 years in federal prison.<\/p>\n\n<p><strong>Threat Mitigation and Strategic Hardening:<\/strong> Network defense against campaigns linked to <strong>REvil (Sodinokibi)<\/strong> requires continuous threat surface management, dark web monitoring for stolen employee credentials, and automated telemetry correlation. Organizations should reference our <a href=\"https:\/\/cyberasia.io\/cyber-risk-checker\/\" style=\"color: #facc15; text-decoration: none;\">Cyber Risk Checker<\/a> and report critical indicators via <a href=\"https:\/\/cyberasia.io\/secure-drop\/\" style=\"color: #facc15; text-decoration: none;\">Secure Drop<\/a>.<\/p>","link":"https:\/\/cyberasia.io\/actor\/revil-sodinokibi\/","name":"REvil (Sodinokibi)","slug":"revil-sodinokibi","taxonomy":"threat_actor","parent":0,"meta":[],"_links":{"self":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/threat_actors\/445","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/threat_actors"}],"about":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/taxonomies\/threat_actor"}],"wp:post_type":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/posts?threat_actors=445"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}