The notorious ransomware gang "REvil" (aka Sodinokibi) has vanished from the Internet without any explanation. The disappearance of REvil occurred around the same time that its representatives were banned from Russian-speaking cybercriminal forums and a group of REvil’s, “Prometheus”, removed all mentions of REvil from its site. The disappearance also came shortly after REvil took responsibility for a large-scale supply-chain attack via the software supplier Kaseya, which allegedly resulted in one million systems being encrypted. It is likely that this attack may have resulted in pressure from law enforcement and possibly arrests of affiliates. It is also possible that REvil may have received a substantial profit from recent campaigns and deliberately shut down operations. Whatever the reason for the group’s disappearance, this event is likely to impact the ransomware threat landscape. REvil was one of the first groups to utilize “double extortion” techniques and set the path many other ransomware groups followed.

×
Want these
Threat Intelligence reports sent straight to your inbox?
Subscribe below!
Thank you!
Error - something went wrong!
Most Recent Flipbooks
Weekly Intelligence Summary 21 October
Main story: Ransom Cartel and REvil: Partners in cybercrime?
Weekly Intelligence Summary 14 Oct
Main story: Hacktivists fan flames of Iranian anti-regime protests
Weekly Intelligence Summary 07 Oct
Main story: ProxyNotShell spells déjà vu for MS Exchange Server defenders
Weekly Intelligence Summary 30 Sept
Main story: Rogue ex-developer leaks LockBit 3.0 builder
Weekly Intelligence Summary 23 Sept
Main story: Uber compromised by Lapsus$'s resurgence
Weekly Intelligence Summary 16 Sept
Main story: Cyber attacks shock the Italian energy sector
Weekly Intelligence Summary 09 Sept
Main story: Back to school for students and ransomware groups