Description Summary
Sodinokibi ransomware group also known as REvil (Ransomware Evil) operates as a ransomware-as-a-service (RaaS) model. After the group compromised his victims, they would threaten to publish the victim's sensitive data on their darknet blog named 'Happy Blog', unless the ransom is paid. The ransomware malware code used by REvil is pretty similar to the ransomware code used by DarkSide - a different threat actor. REvil group claims to steal information after a successful attack on the supplier of the tech giant Apple and stole confidential schematics of their upcoming products.
Threat Actor
Sodinokibi/REvil — GandCrab successor RaaS ('Happy Blog'); Kaseya and JBS supply-chain attacks. ~40% affiliate share.
Technical Indicators
Encryption Extension
.<random per victim>
Encryption Algorithm
Salsa20 (files) + Curve25519/ECDH (key exchange)
Ransom Note Name
[random]-readme.txt
Targeted Industries
Cross-sector, Managed service providers
First Seen
April 2019
Last Seen
2022 (disrupted; Russian FSB arrests Jan 2022)
Geographical Location
Worldwide
MITRE ATT&CK Matrix
| Tactic | TTP | Technique Name |
|---|---|---|
| Impact x 2 | T1486 | Data Encrypted for Impact |
| T1490 | Inhibit System Recovery | |
| Exfiltration x 1 | T1567 | Exfiltration Over Web Service (leak site) |
| Initial Access x 2 | T1190 | Exploit Public-Facing Application |
| T1078 | Valid Accounts |