REvil
   HOME

TheInfoList



OR:

REvil (Ransomware Evil; also known as Sodinokibi) was a Russia-based or Russian-speaking private
ransomware Ransomware is a type of malware from cryptovirology that threatens to publish the victim's personal data or permanently block access to it unless a ransom is paid off. While some simple ransomware may lock the system without damaging any files, ...
-as-a-service (RaaS) operation. After an attack, REvil would threaten to publish the information on their page ''Happy Blog'' unless the
ransom Ransom is the practice of holding a prisoner or item to extort money or property to secure their release, or the sum of money involved in such a practice. When ransom means "payment", the word comes via Old French ''rançon'' from Latin ''red ...
was received. In a high profile case, REvil attacked a supplier of the tech giant
Apple An apple is an edible fruit produced by an apple tree (''Malus domestica''). Apple fruit tree, trees are agriculture, cultivated worldwide and are the most widely grown species in the genus ''Malus''. The tree originated in Central Asia, wh ...
and stole confidential schematics of their upcoming products. In January 2022, the Russian
Federal Security Service The Federal Security Service of the Russian Federation (FSB) RF; rus, Федеральная служба безопасности Российской Федерации (ФСБ России), Federal'naya sluzhba bezopasnosti Rossiyskoy Feder ...
said they had dismantled REvil and charged several of its members.


History

REvil recruits affiliates to distribute the
ransomware Ransomware is a type of malware from cryptovirology that threatens to publish the victim's personal data or permanently block access to it unless a ransom is paid off. While some simple ransomware may lock the system without damaging any files, ...
for them. As part of this arrangement, the affiliates and ransomware developers split revenue generated from ransom payments. It is difficult to pinpoint their exact location, but they are thought to be based in
Russia Russia (, , ), or the Russian Federation, is a List of transcontinental countries, transcontinental country spanning Eastern Europe and North Asia, Northern Asia. It is the List of countries and dependencies by area, largest country in the ...
due to the fact that the group does not target Russian organizations, or those in former
Soviet-bloc The Eastern Bloc, also known as the Communist Bloc and the Soviet Bloc, was the group of socialist states of Central and Eastern Europe, East Asia, Southeast Asia, Africa, and Latin America under the influence of the Soviet Union that existed du ...
countries. Ransomware code used by REvil resembles the code used by DarkSide, a different hacking group; REvil's code is not publicly available, suggesting that DarkSide is an offshoot of REvil or a partner of REvil. REvil and DarkSide use similarly structured ransom notes and the same code to check that the victim is not located in a
Commonwealth of Independent States The Commonwealth of Independent States (CIS) is a regional intergovernmental organization in Eurasia. It was formed following the dissolution of the Soviet Union in 1991. It covers an area of and has an estimated population of 239,796,010. ...
(CIS) country. Cybersecurity experts believe REvil is an offshoot from a previous notorious, but now-defunct hacker gang, GandCrab. This is suspected due to the fact that REvil first became active directly after GandCrab shutdown, and that the ransomware both share a significant amount of code.


2020


May

As part of the criminal cybergang's operations, they are known for stealing nearly one
terabyte The byte is a units of information, unit of digital information that most commonly consists of eight bits. Historically, the byte was the number of bits used to encode a single character (computing), character of text in a computer and for this ...
of information from the law firm Grubman Shire Meiselas & Sacks and demanding a ransom to not publish it. The group had attempted to extort other companies and public figures as well. In May 2020 they demanded $42 million from US president
Donald Trump Donald John Trump (born June 14, 1946) is an American politician, media personality, and businessman who served as the 45th president of the United States from 2017 to 2021. Trump graduated from the Wharton School of the University of Pe ...
. The group claimed to have done this by deciphering the
elliptic-curve cryptography Elliptic-curve cryptography (ECC) is an approach to public-key cryptography based on the algebraic structure of elliptic curves over finite fields. ECC allows smaller keys compared to non-EC cryptography (based on plain Galois fields) to provide eq ...
that the firm used to protect its data. According to an interview with an alleged member, they found a buyer for Trump information, but this cannot be confirmed. In the same interview, the member claimed that they would bring in $100
million One million (1,000,000), or one thousand thousand, is the natural number following 999,999 and preceding 1,000,001. The word is derived from the early Italian ''millione'' (''milione'' in modern Italian), from ''mille'', "thousand", plus the au ...
ransoms in 2020. On 16 May 2020, the group released legal documents totaling a size of 2.4 GB related to the singer
Lady Gaga Stefani Joanne Angelina Germanotta ( ; born March 28, 1986), known professionally as Lady Gaga, is an American singer, songwriter, and actress. She is known for her image reinventions and musical versatility. Gaga began performing as a teenag ...
. The following day, they released 169 "harmless" e-mails which referred to Donald Trump or contained the word 'trump'. They were planning on selling
Madonna's Madonna Louise Ciccone (; ; born August 16, 1958) is an American singer-songwriter and actress. Widely dubbed the " Queen of Pop", Madonna has been noted for her continual reinvention and versatility in music production, songwriting, a ...
information, but eventually reneged.


2021


March

On 27 March 2021, REvil attacked
Harris Federation Harris Federation is a multi-academy trust of 52 primary and secondary academies in and around London. They are sponsored by Philip Harris (Lord Harris of Peckham). Description With 52 academies in London and Essex, the Harris Federation educates ...
and published multiple financial documents of the federation to its blog. As a result, the IT systems of the federation were shut down for some weeks, affecting up to 37,000 students. On 18 March 2021, an REvil affiliate claimed on their data leak site that they had downloaded data from multinational hardware and
electronics The field of electronics is a branch of physics and electrical engineering that deals with the emission, behaviour and effects of electrons using electronic devices. Electronics uses active devices to control electron flow by amplification ...
corporation Acer, as well as installing ransomware, which has been linked to the 2021 Microsoft Exchange Server data breach by cybersecurity firm Advanced Intel, which found first signs of Acer servers being targeted from 5 March 2021. A US$50 million ransom was demanded to decrypt the undisclosed number of systems and for the downloaded files to be deleted, increasing to US$100 million if not paid by 28 March 2021.


April

In April 2021, REvil stole plans for upcoming Apple products from
Quanta Computer Quanta Computer Incorporated () () is a Taiwan-based manufacturer of notebook computers and other electronic hardware. Its customers include Apple Inc., Dell, Hewlett-Packard Inc., Acer Inc., Alienware, Amazon.com, Cisco, Fujitsu, Gericom, Lenov ...
, including purported plans for Apple laptops and an Apple Watch. REvil threatened to release the plans publicly unless they receive $50 million.


May

On 30 May 2021,
JBS S.A. JBS S.A. is a Brazilian company that is the largest meat processing company (by sales) in the world, producing factory processed beef, chicken and pork, and also selling by-products from the processing of these meats. It is headquartered in Sã ...
was attacked by ransomware which forced the temporary shutdown of all the company’s U.S. beef plants and disrupted operations at poultry and pork plants. A few days later, the
White House The White House is the official residence and workplace of the president of the United States. It is located at 1600 Pennsylvania Avenue NW in Washington, D.C., and has been the residence of every U.S. president since John Adams in 1800. ...
announced that REvil may be responsible for the
JBS S.A. cyberattack On May 30, 2021, JBS S.A., a Brazil-based meat processing company, suffered a cyberattack, disabling its beef and pork slaughterhouses. The attack impacted facilities in the United States, Canada, and Australia. Background JBS S.A., a Brazil-bas ...
. The
FBI The Federal Bureau of Investigation (FBI) is the domestic Intelligence agency, intelligence and Security agency, security service of the United States and its principal Federal law enforcement in the United States, federal law enforcement age ...
confirmed the connection in a follow-up statement on
Twitter Twitter is an online social media and social networking service owned and operated by American company Twitter, Inc., on which users post and interact with 280-character-long messages known as "tweets". Registered users can post, like, and ...
. JBS paid an $11 million ransom in
Bitcoin Bitcoin ( abbreviation: BTC; sign: ₿) is a decentralized digital currency that can be transferred on the peer-to-peer bitcoin network. Bitcoin transactions are verified by network nodes through cryptography and recorded in a public distr ...
to REvil.


June

On 11 June 2021,
Invenergy Invenergy is an American based multinational power generation development and operations company. The company develops, builds, owns and operates power generation and energy storage projects in the Americas, Europe and Asia, including wind, solar, ...
reported that they were attacked by ransomware. Later, REvil claimed to be responsible.


July

On 2 July 2021, hundreds of
managed service provider Managed services is the practice of outsourcing the responsibility for maintaining, and anticipating need for, a range of processes and functions, ostensibly for the purpose of improved operations and reduced budgetary expenditures through the re ...
s had REvil ransomware dropped on their systems through Kaseya desktop management software. REvil demanded $70 million to restore
encrypted In cryptography, encryption is the process of encoding information. This process converts the original representation of the information, known as plaintext, into an alternative form known as ciphertext. Ideally, only authorized parties can decip ...
data. As a consequence the Swedish
Coop Coop, COOP, Co-op, or ''variation'', most often refers to: * A chicken coop or other enclosure * Cooperative or co-operative ("co-op"), an association of persons who cooperate for their mutual social, economic, and cultural benefit ** Housing ...
grocery store chain was forced to close 800 stores during several days. On 7 July 2021, REvil hacked the computers of
Florida Florida is a state located in the Southeastern region of the United States. Florida is bordered to the west by the Gulf of Mexico, to the northwest by Alabama, to the north by Georgia, to the east by the Bahamas and Atlantic Ocean, and to ...
-based space and weapon-launch technology contractor HX5, which counts the
Army An army (from Old French ''armee'', itself derived from the Latin verb ''armāre'', meaning "to arm", and related to the Latin noun ''arma'', meaning "arms" or "weapons"), ground force or land force is a fighting force that fights primarily on ...
,
Navy A navy, naval force, or maritime force is the branch of a nation's armed forces principally designated for naval warfare, naval and amphibious warfare; namely, lake-borne, riverine, littoral zone, littoral, or ocean-borne combat operations and ...
,
Air Force An air force – in the broadest sense – is the national military branch that primarily conducts aerial warfare. More specifically, it is the branch of a nation's armed services that is responsible for aerial warfare as distinct from an a ...
, and
NASA The National Aeronautics and Space Administration (NASA ) is an independent agency of the US federal government responsible for the civil space program, aeronautics research, and space research. NASA was established in 1958, succeeding t ...
among its clients, publicly releasing stolen documents on its Happy Blog.
The New York Times ''The New York Times'' (''the Times'', ''NYT'', or the Gray Lady) is a daily newspaper based in New York City with a worldwide readership reported in 2020 to comprise a declining 840,000 paid print subscribers, and a growing 6 million paid ...
judged the documents to not be of "vital consequence". After a July 9 phone call between United States president Joe Biden and Russian president
Vladimir Putin Vladimir Vladimirovich Putin; (born 7 October 1952) is a Russian politician and former intelligence officer who holds the office of president of Russia. Putin has served continuously as president or prime minister since 1999: as prime min ...
, Biden told the press, "I made it very clear to him that the United States expects when a ransomware operation is coming from his soil even though it’s not sponsored by the state, we expect them to act if we give them enough information to act on who that is." Biden later added that the United States would take the group's servers down if Putin did not. On 13 July 2021, REvil websites and other infrastructure vanished from the internet.
Politico ''Politico'' (stylized in all caps), known originally as ''The Politico'', is an American, German-owned political journalism newspaper company based in Arlington County, Virginia, that covers politics and policy in the United States and intern ...
cited an unnamed senior administration official as stating that "we don't know exactly why they've
Evil Evil, in a general sense, is defined as the opposite or absence of good. It can be an extremely broad concept, although in everyday usage it is often more narrowly used to talk about profound wickedness and against common good. It is general ...
stood down;" the official also did not discount the possibility that Russia shut down the group or forced it to shut down. On 23 July 2021, Kaseya announced it had received the decryption key for the files encrypted in the July 2
Kaseya VSA ransomware attack On 2 July 2021, a number of managed service providers (MSPs) and their customers became victims of a ransomware attack perpetrated by the REvil group, causing widespread downtime for over 1,000 companies. Company Kaseya Limited is an American s ...
from an unnamed "trusted third party", later discovered to be the FBI who had withheld the key for three weeks, and was helping victims restore their files. The key was withheld to avoid tipping off REvil of an FBI effort to take down their servers, which ultimately proved unnecessary after the hackers went offline without intervention.


September

In September 2021, Romanian cybersecurity firm
Bitdefender Bitdefender is a Romanian cybersecurity technology company headquartered in Bucharest, Romania, with offices in the United States, Europe, Australia and the Middle East. The company was founded in 2001 by the current CEO and main shareholder, ...
published a free universal decryptor utility to help victims of the REvil/Sodinokibi ransomware recover their encrypted files, if they were encrypted before July 13, 2021. From September until early November, the decryptor was used by more than 1,400 companies to avoid paying over $550 million in ransom and allow them to recover their files. On 22 September 2021, malware researchers identified a backdoor built into REvil malware that allowed the original gang members to conduct double-chats and cheat their affiliates out of any ransomware payments. Ransomware affiliates who were cheated reportedly posted their claims on a "Hacker's Court", undermining trust in REvil by affiliates. Newer versions of REvil malware reportedly had the backdoor removed.


October

On 21 October 2021, REvil servers were hacked in a multi-country operation and forced offline.
VMWare VMware, Inc. is an American cloud computing and virtualization technology company with headquarters in Palo Alto, California. VMware was the first commercially successful company to virtualize the x86 architecture. VMware's desktop software ru ...
's head of cybersecurity strategy said "The FBI, in conjunction with Cyber Command, the
Secret Service A secret service is a government agency, intelligence agency, or the activities of a government agency, concerned with the gathering of intelligence data. The tasks and powers of a secret service can vary greatly from one country to another. For ...
and like-minded countries, have truly engaged in significant disruptive actions against these groups,”. A REvil gang member attempted to restore their servers from backups that had also been compromised.


Investigations and criminal charges

As part of Operation GoldDust involving 17 countries, Europol,
Eurojust Eurojust is an agency of the European Union (EU) dealing with judicial co-operation in criminal matters among agencies of the member states. It is seated in The Hague, Netherlands. Established in 2002, it was created to improve handling of seriou ...
and
INTERPOL The International Criminal Police Organization (ICPO; french: link=no, Organisation internationale de police criminelle), commonly known as Interpol ( , ), is an international organization that facilitates worldwide police cooperation and cri ...
, law enforcement authorities arrested five individuals tied to Sodinokibi/REvil and two suspects connected to GandCrab ransomware. They are allegedly responsible for 5000 infections, and collected half a million euros in ransomware payments. On 8 November 2021, the
United States Department of Justice The United States Department of Justice (DOJ), also known as the Justice Department, is a federal executive department of the United States government tasked with the enforcement of federal law and administration of justice in the United State ...
unsealed indictments against Ukrainian national Yaroslav Vasinskyi and Russian national Yevgeniy Polyanin. Vasinskyi was charged with conducting ransomware attacks against multiple victims including Kaseya, and was arrested in Poland on 8 October. Polyanin was charged with conducting ransomware attacks against multiple victims including Texas businesses and government entities. The Department worked with the
National Police of Ukraine The National Police of Ukraine ( uk, Націона́льна полі́ція Украї́ни, translit=Natsionálʹna polítsiya Ukrayíny, ; , NPU), often simply referred to as the ( uk, Поліція, lit=Police, label=none), is the nation ...
for the charges, and also announced the seizure of $6.1 million tied to ransomware payments. If convicted on all charges, Vasinskyi faces a maximum penalty of 115 years in prison, and Polyanin 145 years in prison. In January 2022, the Russian
Federal Security Service The Federal Security Service of the Russian Federation (FSB) RF; rus, Федеральная служба безопасности Российской Федерации (ФСБ России), Federal'naya sluzhba bezopasnosti Rossiyskoy Feder ...
said they had dismantled REvil and charged several of its members after being provided information by the US.


References

{{Hacking in the 2020s Hacker groups Ransomware Cybercrime