Overview

Platforms: Windows
Variants: REvil · Sodin · Sodinokibi
Extensions: —
ATT&CK software: —
Initial access: Spearphishing Attachment
Top countries: —
Observed sectors: —
Tracked victims: 41

Attribution

GOLD SOUTHFIELD / Pinchy Spider VERIFIED
Vendor tracking designation
MITRE ATT&CK links REvil ransomware activity to GOLD SOUTHFIELD, also known as Pinchy Spider.

Affiliates

Yaroslav Vasinskyi (Rabotnik)
Convicted REvil affiliate

Activity

Recent Observations

REvil infrastructure compromised
October 2021
Operational disruption
REvil's Tor payment and data leak infrastructure was compromised, and the operation shut down again.
Kaseya supply-chain attack
July 2021
Major incident
REvil ransomware was distributed through compromised Kaseya VSA infrastructure, affecting managed service providers and downstream organizations worldwide.
Major food-sector disruption
May 2021
Critical infrastructure activity
REvil activity affected a global meat-processing organization and caused disruption to production facilities in the United States and Australia.

TTPs

ATT&CK coverage: 6 techniques · 4 tactics
T1566.001 Spearphishing Attachment
VERIFIED
Initial Access
REvil was distributed through malicious email attachments including Microsoft Word documents.
T1059.001 PowerShell
VERIFIED
Execution
REvil used PowerShell for payload delivery and to remove volume shadow copies.
T1082 System Information Discovery
VERIFIED
Discovery
REvil collected host information including username, computer name, operating system version, language and keyboard layout.
Show more TTPs (3)
T1083 File and Directory Discovery
VERIFIED
Discovery
REvil identified files and directories during its encryption workflow.
T1490 Inhibit System Recovery
VERIFIED
Impact
REvil used tools including vssadmin and bcdedit to delete shadow copies and interfere with recovery mechanisms.
T1486 Data Encrypted for Impact
VERIFIED
Impact
REvil encrypted victim files and demanded payment in exchange for decryption.

Victims

Kaseya CONFIRMED
July 2021 United States Technology
Technology organization in United States.

CVEs

Microsoft — Windows
Sodin/REvil incorporated exploitation of this Windows vulnerability to elevate privileges on compromised systems.
Associated since: April 2019
Oracle — WebLogic Server
Sodin/REvil campaigns exploited vulnerable Oracle WebLogic servers to execute commands and deploy ransomware payloads.
Associated since: April 2019
Pulse Secure — Pulse Connect Secure
CISA reported exploitation of vulnerable Pulse Secure VPN systems followed by deployment of REvil/Sodinokibi ransomware.
Associated since: January 2020

Infrastructure

REvil / Sodinokibi leak site
Tor-hosted infrastructure was used to publish stolen victim data as part of REvil's double-extortion model.
Payment infrastructure
Tor-hosted payment portals were used to deliver ransom demands, communicate with victims and provide decryption material following payment.

Timeline

2024-05
REvil affiliate sentenced
Yaroslav Vasinskyi was sentenced in the United States to more than 13 years in prison for his role in thousands of Sodinokibi/REvil attacks.
2021-11
International enforcement actions
Europol announced arrests of multiple Sodinokibi/REvil affiliates, while U.S. authorities announced charges and seizure of ransomware proceeds.
2021-10
REvil infrastructure compromised
The operation shut down after its Tor infrastructure was compromised and operators lost confidence in the security of their systems.
Show more events (2)
2021-07
Kaseya supply-chain attack
REvil ransomware was distributed through compromised Kaseya VSA infrastructure, affecting service providers and downstream organizations around the world.
2019-04
REvil emerges
Sodinokibi/REvil began operating as a ransomware-as-a-service ecosystem following the decline of GandCrab.

Sources