Revil Ransomware

Description Summary

Sodinokibi ransomware group also known as REvil (Ransomware Evil) operates as a ransomware-as-a-service (RaaS) model. After the group compromised his victims, they would threaten to publish the victim's sensitive data on their darknet blog named 'Happy Blog', unless the ransom is paid. The ransomware malware code used by REvil is pretty similar to the ransomware code used by DarkSide - a different threat actor. REvil group claims to steal information after a successful attack on the supplier of the tech giant Apple and stole confidential schematics of their upcoming products.

Threat Actor

Sodinokibi/REvil — GandCrab successor RaaS ('Happy Blog'); Kaseya and JBS supply-chain attacks. ~40% affiliate share.

Technical Indicators

Encryption Extension
.<random per victim>
Encryption Algorithm
Salsa20 (files) + Curve25519/ECDH (key exchange)
Ransom Note Name
[random]-readme.txt
Targeted Industries
Cross-sector, Managed service providers
First Seen
April 2019
Last Seen
2022 (disrupted; Russian FSB arrests Jan 2022)
Geographical Location
Worldwide

MITRE ATT&CK Matrix

Tactic TTP Technique Name
Impact x 2 T1486 Data Encrypted for Impact
T1490 Inhibit System Recovery
Exfiltration x 1 T1567 Exfiltration Over Web Service (leak site)
Initial Access x 2 T1190 Exploit Public-Facing Application
T1078 Valid Accounts