revil logo

revil

1 incidentes 0 paises 1 sectores ransomware RU Ultimo: 2026-06-25
Aliases: Ransomware Evil, Sodin, Sodinokibi
Ver en IntelTracker → APTTrail →
REvil, also known as Sodinokibi, is a Russia-based or Russian-speaking ransomware-as-a-service (RaaS) operation that emerged in early 2019. This financially motivated group quickly gained prominence for executing high-profile attacks and employing a ruthless dual extortion strategy where they not only encrypt victim data but also exfiltrate sensitive information, threatening to publish it on their 'Happy Blog' darknet site unless a ransom is paid. The group is widely believed to be an evolution of the defunct GandCrab ransomware operation due to significant code similarities and the timing of its emergence. A notable distinguishing characteristic of REvil is its policy of avoiding targets within Commonwealth of Independent States (CIS) countries, a geographic carve-out often hardcoded into its malware. REvil was responsible for several high-impact incidents, including attacks against major meat supplier JBS and the Kaseya software company.
Malware asociado
Backdoor:Win32/Simda, win.squirrelwaffle, win.feodo, win.virut, Sodinokibi, Storm-0978
Tecnicas MITRE
T1127 - Trusted Developer Utilities Proxy Execution, T1124 - System Time Discovery, T1033 - System Owner/User Discovery, T1057 - Process Discovery, T1106 - Native API, T1071 - Application Layer Protocol
CVEs relacionadas
CVE-2026-34040, CVE-2026-1340, CVE-2025-23121, CVE-2025-23120, CVE-2024-41110, CVE-2024-40711

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises objetivo (SOCRadar)

United Arab EmiratesArmeniaArgentinaAustraliaBermudaBrazilBelarusCanadaChileChina

Sectores atacados

Tech (1)

Sectores objetivo (SOCRadar)

Construction of BuildingsFood ManufacturingOther Information ServicesSoftware PublishersReal EstateHospitalsAccommodationAir TransportationManufacturingConstruction

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com