REvil (Ransomware Evil; also known as Sodinokibi) was a Russia-based or Russian-speaking private
ransomware
Ransomware is a type of malware that Encryption, encrypts the victim's personal data until a ransom is paid. Difficult-to-trace Digital currency, digital currencies such as paysafecard or Bitcoin and other cryptocurrency, cryptocurrencies are com ...
-as-a-service (RaaS) operation. After an attack, REvil would threaten to publish the information on their page ''Happy Blog'' unless the
ransom
Ransom refers to the practice of holding a prisoner or item to extort money or property to secure their release. It also refers to the sum of money paid by the other party to secure a captive's freedom.
When ransom means "payment", the word ...
was received. In a high profile case, REvil attacked a supplier of the tech giant
Apple
An apple is a round, edible fruit produced by an apple tree (''Malus'' spp.). Fruit trees of the orchard or domestic apple (''Malus domestica''), the most widely grown in the genus, are agriculture, cultivated worldwide. The tree originated ...
and stole confidential schematics of their upcoming products. In January 2022, the Russian
Federal Security Service
The Federal Security Service of the Russian Federation �СБ, ФСБ России (FSB) is the principal security agency of Russia and the main successor agency to the Soviet Union's KGB; its immediate predecessor was the Federal Counterin ...
said they had dismantled REvil and charged several of its members.
History
REvil recruits affiliates to distribute the
ransomware
Ransomware is a type of malware that Encryption, encrypts the victim's personal data until a ransom is paid. Difficult-to-trace Digital currency, digital currencies such as paysafecard or Bitcoin and other cryptocurrency, cryptocurrencies are com ...
for them. As part of this arrangement, the affiliates and ransomware developers split revenue generated from ransom payments. It is difficult to pinpoint their exact location, but they are thought to be based in
Russia
Russia, or the Russian Federation, is a country spanning Eastern Europe and North Asia. It is the list of countries and dependencies by area, largest country in the world, and extends across Time in Russia, eleven time zones, sharing Borders ...
due to the fact that the group does not target Russian organizations, or those in former
Soviet-bloc countries.
Ransomware code used by REvil resembles the code used by
DarkSide, a different hacking group; REvil's code is not publicly available, suggesting that DarkSide is an offshoot of REvil or a partner of REvil. REvil and DarkSide use similarly structured ransom notes and the same code to check that the victim is not located in a
Commonwealth of Independent States
The Commonwealth of Independent States (CIS) is a regional organization, regional intergovernmental organization in Eurasia. It was formed following the dissolution of the Soviet Union, dissolution of the Soviet Union in 1991. It covers an ar ...
(CIS) country.
Cybersecurity experts believe REvil is an offshoot from a previous notorious, but now-defunct hacker gang, GandCrab. This is suspected due to the fact that REvil first became active directly after GandCrab shutdown, and that the ransomware both share a significant amount of code.
2020
May
As part of the criminal cybergang's operations, they are known for stealing nearly one
terabyte
The byte is a unit of digital information that most commonly consists of eight bits. Historically, the byte was the number of bits used to encode a single character of text in a computer and for this reason it is the smallest addressable un ...
of information from the law firm Grubman Shire Meiselas & Sacks and demanding a ransom to not publish it.
The group had attempted to extort other companies and public figures as well.
In May 2020 they demanded $42 million from US president
Donald Trump
Donald John Trump (born June 14, 1946) is an American politician, media personality, and businessman who is the 47th president of the United States. A member of the Republican Party (United States), Republican Party, he served as the 45 ...
. The group claimed to have done this by deciphering the
elliptic-curve cryptography
Elliptic-curve cryptography (ECC) is an approach to public-key cryptography based on the algebraic structure of elliptic curves over finite fields. ECC allows smaller keys to provide equivalent security, compared to cryptosystems based on modula ...
that the firm used to protect its data. According to an interview with an alleged member, they found a buyer for Trump information, but this cannot be confirmed. In the same interview, the member claimed that they would bring in $100
million
1,000,000 (one million), or one thousand thousand, is the natural number following 999,999 and preceding 1,000,001. The word is derived from the early Italian ''millione'' (''milione'' in modern Italian), from ''mille'', "thousand", plus the ...
ransoms in 2020.
On 16 May 2020, the group released legal documents totaling a size of 2.4 GB related to the singer
Lady Gaga
Stefani Joanne Angelina Germanotta (born March 28, 1986), known professionally as Lady Gaga, is an American singer, songwriter, and actress. Known for her image reinventions and versatility across the entertainment industry, she is an influ ...
. The following day, they released 169 "harmless" e-mails which referred to Donald Trump or contained the word 'trump'.
They were planning on selling
Madonna's information, but eventually reneged.
2021
March
On 27 March 2021, REvil attacked
Harris Federation
Harris Federation is a multi-academy trust of 52 primary and secondary academies in and around London. They are sponsored by Philip Harris (Lord Harris of Peckham).
Description
With 52 academies in London and Essex, the Harris Federation educat ...
and published multiple financial documents of the federation to its blog. As a result, the IT systems of the federation were shut down for some weeks, affecting up to 37,000 students.
On 18 March 2021, an REvil affiliate claimed on their data leak site that they had downloaded data from multinational hardware and
electronics
Electronics is a scientific and engineering discipline that studies and applies the principles of physics to design, create, and operate devices that manipulate electrons and other Electric charge, electrically charged particles. It is a subfield ...
corporation
Acer, as well as installing ransomware, which has been linked to the
2021 Microsoft Exchange Server data breach by cybersecurity firm Advanced Intel, which found first signs of Acer servers being targeted from 5 March 2021. A US$50 million ransom was demanded to decrypt the undisclosed number of systems and for the downloaded files to be deleted, increasing to US$100 million if not paid by 28 March 2021.
April
In April 2021, REvil stole plans for upcoming Apple products from
Quanta Computer
Quanta Computer Incorporated () () is a Taiwan-based contracted manufacturer of electronic hardware.
Quanta's business extends to enterprise network systems, home entertainment, mobile communication, automotive electronics, and digital home ma ...
, including purported plans for Apple laptops and an Apple Watch. REvil threatened to release the plans publicly unless they receive $50 million.
May
On 30 May 2021,
JBS S.A.
JBS S.A. is a Brazilian multinational company that is the largest meat processing enterprise in the world, producing factory processed beef, chicken, salmon, sheep, pork, and also selling by-products from the processing of these meats. It is he ...
was attacked by ransomware which forced the temporary shutdown of all the company’s U.S. beef plants and disrupted operations at poultry and pork plants. A few days later, the
White House
The White House is the official residence and workplace of the president of the United States. Located at 1600 Pennsylvania Avenue Northwest (Washington, D.C.), NW in Washington, D.C., it has served as the residence of every U.S. president ...
announced that REvil may be responsible for the
JBS S.A. cyberattack. The
FBI
The Federal Bureau of Investigation (FBI) is the domestic Intelligence agency, intelligence and Security agency, security service of the United States and Federal law enforcement in the United States, its principal federal law enforcement ag ...
confirmed the connection in a follow-up statement on
Twitter
Twitter, officially known as X since 2023, is an American microblogging and social networking service. It is one of the world's largest social media platforms and one of the most-visited websites. Users can share short text messages, image ...
. JBS paid an $11 million ransom in
Bitcoin
Bitcoin (abbreviation: BTC; Currency symbol, sign: ₿) is the first Decentralized application, decentralized cryptocurrency. Based on a free-market ideology, bitcoin was invented in 2008 when an unknown entity published a white paper under ...
to REvil.
June
On 11 June 2021,
Invenergy
Invenergy is an American based multinational power generation development and operations company. The company develops, builds, owns and operates power generation and energy storage projects in the Americas, Europe and Asia, including wind, solar, ...
reported that they were attacked by ransomware. Later, REvil claimed to be responsible.
July
On 2 July 2021, hundreds of
managed service provider
Managed services is the practice of outsourcing the responsibility for maintaining, and anticipating need for, a range of processes and functions, ostensibly for the purpose of improved operations and reduced budgetary expenditures through the ...
s had REvil ransomware dropped on their systems through Kaseya desktop management software. REvil demanded $70 million to restore
encrypted
In cryptography, encryption (more specifically, encoding) is the process of transforming information in a way that, ideally, only authorized parties can decode. This process converts the original representation of the information, known as plain ...
data. As a consequence the Swedish
Coop
Coop or Co-op most often refer to:
* Chicken coop or other animal enclosure
* Cooperative or co-operative ("co-op"), an association co-operating for mutual social, economic or cultural benefit
** Consumer cooperative
** Food cooperative
** Housin ...
grocery store chain was forced to close 800 stores during several days.
On 7 July 2021, REvil hacked the computers of
Florida
Florida ( ; ) is a U.S. state, state in the Southeastern United States, Southeastern region of the United States. It borders the Gulf of Mexico to the west, Alabama to the northwest, Georgia (U.S. state), Georgia to the north, the Atlantic ...
-based space and weapon-launch technology contractor HX5, which counts the
Army
An army, ground force or land force is an armed force that fights primarily on land. In the broadest sense, it is the land-based military branch, service branch or armed service of a nation or country. It may also include aviation assets by ...
,
Navy
A navy, naval force, military maritime fleet, war navy, or maritime force is the military branch, branch of a nation's armed forces principally designated for naval warfare, naval and amphibious warfare; namely, lake-borne, riverine, littoral z ...
,
Air Force
An air force in the broadest sense is the national military branch that primarily conducts aerial warfare. More specifically, it is the branch of a nation's armed services that is responsible for aerial warfare as distinct from an army aviati ...
, and
NASA
The National Aeronautics and Space Administration (NASA ) is an independent agencies of the United States government, independent agency of the federal government of the United States, US federal government responsible for the United States ...
among its clients, publicly releasing stolen documents on its Happy Blog.
The New York Times
''The New York Times'' (''NYT'') is an American daily newspaper based in New York City. ''The New York Times'' covers domestic, national, and international news, and publishes opinion pieces, investigative reports, and reviews. As one of ...
judged the documents to not be of "vital consequence".
After a July 9 phone call between United States president
Joe Biden
Joseph Robinette Biden Jr. (born November 20, 1942) is an American politician who was the 46th president of the United States from 2021 to 2025. A member of the Democratic Party (United States), Democratic Party, he served as the 47th vice p ...
and Russian president
Vladimir Putin
Vladimir Vladimirovich Putin (born 7 October 1952) is a Russian politician and former intelligence officer who has served as President of Russia since 2012, having previously served from 2000 to 2008. Putin also served as Prime Minister of Ru ...
, Biden told the press, "I made it very clear to him that the United States expects when a ransomware operation is coming from his soil even though it’s not sponsored by the state, we expect them to act if we give them enough information to act on who that is." Biden later added that the United States would take the group's servers down if Putin did not.
On 13 July 2021, REvil websites and other infrastructure vanished from the internet.
Politico
''Politico'' (stylized in all caps), known originally as ''The Politico'', is an American political digital newspaper company founded by American banker and media executive Robert Allbritton in 2007. It covers politics and policy in the Unit ...
cited an unnamed senior administration official as stating that "we don't know exactly why they've
Evil
Evil, as a concept, is usually defined as profoundly immoral behavior, and it is related to acts that cause unnecessary pain and suffering to others.
Evil is commonly seen as the opposite, or sometimes absence, of good. It can be an extreme ...
stood down;" the official also did not discount the possibility that Russia shut down the group or forced it to shut down.
On 23 July 2021, Kaseya announced it had received the decryption key for the files encrypted in the July 2
Kaseya VSA ransomware attack
On 2 July 2021, a number of managed service providers (MSPs) and their customers became victims of a ransomware attack perpetrated by the REvil group, causing widespread downtime for over 1,000 companies. The attack was carried out by exploiting ...
from an unnamed "trusted third party", later discovered to be the FBI who had withheld the key for three weeks, and was helping victims restore their files. The key was withheld to avoid tipping off REvil of an FBI effort to take down their servers, which ultimately proved unnecessary after the hackers went offline without intervention.
September
In September 2021, Romanian cybersecurity firm
Bitdefender
Bitdefender is a multinational cybersecurity technology company dual-headquartered in Bucharest, Romania and Santa Clara, California, with offices in the United States, Europe, Australia and the Middle East.
The company was founded in 2001 by c ...
published a free universal decryptor utility to help victims of the REvil/Sodinokibi ransomware recover their encrypted files, if they were encrypted before July 13, 2021. From September until early November, the decryptor was used by more than 1,400 companies to avoid paying over $550 million in ransom and allow them to recover their files.
On 22 September 2021, malware researchers identified a backdoor built into REvil malware that allowed the original gang members to conduct double-chats and cheat their affiliates out of any ransomware payments. Ransomware affiliates who were cheated reportedly posted their claims on a "Hacker's Court", undermining trust in REvil by affiliates. Newer versions of REvil malware reportedly had the backdoor removed.
October
On 21 October 2021, REvil servers were hacked in a multi-country operation and forced offline.
VMWare's head of cybersecurity strategy said "The FBI, in conjunction with
Cyber Command
United States Cyber Command (USCYBERCOM) is one of the eleven unified combatant commands of the United States Department of Defense (DoD). It unifies the direction of cyberspace operations, strengthens DoD cyberspace capabilities, and integrat ...
, the
Secret Service
A secret service is a government agency, intelligence agency, or the activities of a government agency, concerned with the gathering of intelligence data. The tasks and powers of a secret service can vary greatly from one country to another. For i ...
and like-minded countries, have truly engaged in significant disruptive actions against these groups,”. A REvil gang member attempted to restore their servers from backups that had also been compromised.
Investigations and criminal charges
As part of Operation GoldDust involving 17 countries,
Europol
Europol, officially the European Union Agency for Law Enforcement Cooperation, is the law enforcement agency of the European Union (EU). Established in 1998, it is based in The Hague, Netherlands, and serves as the central hub for coordinating c ...
,
Eurojust
The European Union Agency for Criminal Justice Cooperation (Eurojust) is an agency of the European Union (EU) dealing with judicial co-operation in criminal matters among agencies of the member states. It is seated in The Hague, Netherlands. Est ...
and
INTERPOL
The International Criminal Police Organization – INTERPOL (abbreviated as ICPO–INTERPOL), commonly known as Interpol ( , ; stylized in allcaps), is an international organization that facilitates worldwide police cooperation and crime cont ...
, law enforcement authorities arrested five individuals tied to Sodinokibi/REvil and two suspects connected to GandCrab ransomware. They are allegedly responsible for 5,000 infections, and collected half a million euros in ransomware payments.
On 8 November 2021, the
United States Department of Justice
The United States Department of Justice (DOJ), also known as the Justice Department, is a United States federal executive departments, federal executive department of the U.S. government that oversees the domestic enforcement of Law of the Unite ...
unsealed indictments against Ukrainian national Yaroslav Vasinskyi and Russian national Yevgeniy Polyanin. Vasinskyi was charged with conducting ransomware attacks against multiple victims including Kaseya, and Polyanin was charged with conducting ransomware attacks against multiple victims including Texas businesses and government entities. The Department worked with the
National Police of Ukraine
The National Police of Ukraine (, ; /NPU ), often simply referred to as the (), is the national, and only, police service of Ukraine. It was formed on 3 July 2015, as part of the post-Euromaidan reforms launched by Ukrainian president Petro Por ...
for the charges, and also announced the seizure of $6.1 million tied to ransomware payments. Vasinskyi, also known as Rabotnik, was arrested while crossing the border from Ukraine to Poland on 8 October 2021 and was extradited to the United States in 2022. He pleaded guilty to cybercrime and money laundering charges, and on 1 May 2024 was sentenced to 13 years and seven months in prison and ordered to pay $16 million in restitution. , Polyanin remains at large, and is thought by the FBI to reside in Russia, possibly in
Barnaul
Barnaul (, ) is the largest types of inhabited localities in Russia, city and administrative centre of Altai Krai, Russia, located at the confluence of the Barnaulka and Ob (river), Ob rivers in the West Siberian Plain. As of the Russian Censu ...
.
In January 2022, the Russian
Federal Security Service
The Federal Security Service of the Russian Federation �СБ, ФСБ России (FSB) is the principal security agency of Russia and the main successor agency to the Soviet Union's KGB; its immediate predecessor was the Federal Counterin ...
said they had dismantled REvil and charged several of its members after being provided information by the US.
The Fluffy
There is a hacker group called Fluffy with Headquarters in Corrèze, known to have an affiliation with REvil, that primarily uses
typosquatting
Typosquatting, also called URL hijacking, a sting site, a cousin domain, or a fake URL, is a form of cybersquatting, and possibly brandjacking which relies on mistakes such as typos made by Internet users when inputting a website address into ...
,
cybersquatting
Cybersquatting (also known as domain squatting) is the practice of registering, trafficking in, or using an Internet domain name, with a bad faith intent to profit from the goodwill of a trademark belonging to someone else.
The term is derived ...
and
keyword stuffing
Spamdexing (also known as search engine spam, search engine poisoning, black-hat search engine optimization, search spam or web spam) is the deliberate manipulation of search engine indexes. It involves a number of methods, such as link building a ...
. This hacker group has distributed Magniber ransomware, Sodinokibi, and GandCrab, BlueCrab (It is the next version of GandCrab is the same variant that was used in the
Kaseya VSA ransomware attack
On 2 July 2021, a number of managed service providers (MSPs) and their customers became victims of a ransomware attack perpetrated by the REvil group, causing widespread downtime for over 1,000 companies. The attack was carried out by exploiting ...
). In France, it is known as Fluffy, in Germany as Talentfrei, in Australia and English speaking countries as "Emma Hill", and in South Korea as Nebomi (meaning "Four Seasons Blossom" in Korean). Fluffy is known to have claimed a number of victims, especially in South Korea.
The campaign in which Fluffy first targeted South Korea is known as Magniber, and it utilized an
exploit kit
An exploit kit is a tool used for automatically managing and deploying Exploit (computer security), exploits against a target computer. Exploit kits allow attackers to deliver malware without having advanced knowledge of the exploits being used. ...
before the emergence of various modified
payloads. The techniques employed by these modified payloads vary, but they share a commonality in utilizing standardized technologies supported by web browsers or operating systems, such as
URI
Uri may refer to:
Places
* Canton of Uri, a canton in Switzerland
* Úri, a village and commune in Hungary
* Uri, Iran, a village in East Azerbaijan Province
* Uri, Jammu and Kashmir, a town in India
* Uri (island), off Malakula Island in V ...
scheme and
BASE64
In computer programming, Base64 is a group of binary-to-text encoding schemes that transforms binary data into a sequence of printable characters, limited to a set of 64 unique characters. More specifically, the source binary data is taken 6 bits ...
, unlike exploit kits that leverage
zero-day vulnerabilities. Users receive security warnings from their operating systems before executing the files; however, the information provided by the attackers is often sufficient for users to decide to disregard the security alerts.
Following the introduction of these altered payloads in South Korea, Fluffy immediately referred to themselves as Nebomi and continued with ransomware attacks. The Seoul Central District Prosecutors' Office announced in November 2023 that accomplices assisting them in South Korea were prosecuted. According to the announcement, during the process of investigating the suspects, records of funds being transferred to
Lazarus Group
The Lazarus Group (also known as Guardians of Peace or Whois Team
) is a hacker group made up of an unknown number of individuals, alleged to be run by the government of North Korea. While not much is known about the group, researchers have at ...
were also discovered. It is unclear whether it is related to the ongoing ransomware investigation, but according to a media report in December 2023, The
Supreme Court of Korea
The Supreme Court of Korea () is the highest ordinary court in the judicial branch of South Korea, seated in Seocho, Seoul. Established under Chapter 5 of the Constitution of South Korea, the court has ultimate and comprehensive jurisdictio ...
claimed that it experienced a cyberattack by the Lazarus Group, resulting in the leakage of sensitive data.
Fluffy is presumed to assist in the distribution of various types of ransomware, ranging from Magniber and REvil to
LockBit
LockBit is a cybercriminal group proposing ransomware as a service (RaaS). Software developed by the group (also called ransomware) enables malicious actors who are willing to pay for using it to carry out attacks in two tactics where they not o ...
, leveraging successful cases of
watering hole attacks they have executed. For example, it is believed that they may be implicated in incidents such as the successful cyber attack on
Toshiba
is a Japanese multinational electronics company headquartered in Minato, Tokyo. Its diversified products and services include power, industrial and social infrastructure systems, elevators and escalators, electronic components, semiconductors ...
's French branch in May 2021, the claimed cyber attack on the
Doosan Group
Doosan Group () is a South Korean multinational conglomerate corporation. In 2009, the corporation was placed in the ''Fortune'' Global 500 index. It is the parent company of Bobcat and Škoda Power. Doosan Group is the oldest running company ...
in August 2022, and the claimed cyber attack on the
National Tax Service (South Korea)
The National Tax Service () is the tax organization in South Korea
South Korea, officially the Republic of Korea (ROK), is a country in East Asia. It constitutes the southern half of the Korea, Korean Peninsula and borders North Korea alo ...
in March 2023.
At times, they employed relatively simple methods, such as emails, for the distribution of REvil ransomware (also known as GandCrab). The content of these emails typically involved impersonating law enforcement agencies. The senders of these emails were two individuals under the age of 19, who claimed to have committed such crimes in response to a proposition that said, "If you join in sending ransomware, we'll share the profits." In the trial held at the Seoul Central District Court in August 2021, they were sentenced to 2 years and 1 year 6 months of imprisonment. One of them had already received a 10-year prison sentence for participating in another campaign.
References
{{Hacking in the 2020s
Hacker groups
Ransomware
Cybercrime