Overview
Platforms:
Windows
Variants:
REvil · Sodin · Sodinokibi
Extensions:
—
ATT&CK software:
—
Initial access:
Spearphishing Attachment
Top countries:
—
Observed sectors:
—
Tracked victims:
41
Attribution
GOLD SOUTHFIELD / Pinchy Spider
VERIFIED
Vendor tracking designation
MITRE ATT&CK links REvil ransomware activity to GOLD SOUTHFIELD, also known as Pinchy Spider.
Affiliates
Yaroslav Vasinskyi (Rabotnik)
Convicted REvil affiliate
Activity
Recent Observations
REvil infrastructure compromised
October 2021
Operational disruption
REvil's Tor payment and data leak infrastructure was compromised, and the operation shut down again.
Kaseya supply-chain attack
July 2021
Major incident
REvil ransomware was distributed through compromised Kaseya VSA infrastructure, affecting managed service providers and downstream organizations worldwide.
Major food-sector disruption
May 2021
Critical infrastructure activity
REvil activity affected a global meat-processing organization and caused disruption to production facilities in the United States and Australia.
TTPs
ATT&CK coverage:
6 techniques
· 4 tactics
T1566.001
Spearphishing Attachment
VERIFIEDInitial Access
REvil was distributed through malicious email attachments including Microsoft Word documents.
T1059.001
PowerShell
VERIFIEDExecution
REvil used PowerShell for payload delivery and to remove volume shadow copies.
T1082
System Information Discovery
VERIFIEDDiscovery
REvil collected host information including username, computer name, operating system version, language and keyboard layout.
Show more TTPs (3)
T1083
File and Directory Discovery
VERIFIEDDiscovery
REvil identified files and directories during its encryption workflow.
T1490
Inhibit System Recovery
VERIFIEDImpact
REvil used tools including vssadmin and bcdedit to delete shadow copies and interfere with recovery mechanisms.
T1486
Data Encrypted for Impact
VERIFIEDImpact
REvil encrypted victim files and demanded payment in exchange for decryption.
Victims
Kaseya
CONFIRMED
Technology organization in United States.
CVEs
Microsoft
— Windows
Sodin/REvil incorporated exploitation of this Windows vulnerability to elevate privileges on compromised systems.
Associated since:
April 2019
Oracle
— WebLogic Server
Sodin/REvil campaigns exploited vulnerable Oracle WebLogic servers to execute commands and deploy ransomware payloads.
Associated since:
April 2019
Pulse Secure
— Pulse Connect Secure
CISA reported exploitation of vulnerable Pulse Secure VPN systems followed by deployment of REvil/Sodinokibi ransomware.
Associated since:
January 2020
Infrastructure
REvil / Sodinokibi leak site
Tor-hosted infrastructure was used to publish stolen victim data as part of REvil's double-extortion model.
Payment infrastructure
Tor-hosted payment portals were used to deliver ransom demands, communicate with victims and provide decryption material following payment.
Timeline
2024-05
REvil affiliate sentenced
Yaroslav Vasinskyi was sentenced in the United States to more than 13 years in prison for his role in thousands of Sodinokibi/REvil attacks.
2021-11
International enforcement actions
Europol announced arrests of multiple Sodinokibi/REvil affiliates, while U.S. authorities announced charges and seizure of ransomware proceeds.
2021-10
REvil infrastructure compromised
The operation shut down after its Tor infrastructure was compromised and operators lost confidence in the security of their systems.
Show more events (2)
2021-07
Kaseya supply-chain attack
REvil ransomware was distributed through compromised Kaseya VSA infrastructure, affecting service providers and downstream organizations around the world.
2019-04
REvil emerges
Sodinokibi/REvil began operating as a ransomware-as-a-service ecosystem following the decline of GandCrab.
Sources
Sodinokibi/REvil Affiliate Sentenced for Role in $700M Ransomware Scheme
U.S. Department of Justice
Show more sources (7)
Ukrainian Arrested and Charged with Ransomware Attack on Kaseya
U.S. Department of Justice
Sodin ransomware exploits Windows vulnerability and processor architecture
Kaspersky Securelist
Attorney General Merrick B. Garland, Deputy Attorney General Lisa O. Monaco and FBI Director Christopher Wray Deliver Remarks on Sodinokibi/REvil Ransomware Arrest
U.S. Department of Justice
Government advisory