REvil, also known as Sodinokibi, is a ransomware-as-a-service (RaaS) family first observed in April 2019, operated by the threat group tracked as PINCHY SPIDER (also linked to UNKN). It is categorized as a ransomware with data-theft extortion capabilities, and its operators rent the malware to affiliates who conduct attacks in exchange for a percentage of ransom payments.
REvil encrypts files using Salsa20 for per-file keys, which are then wrapped with RSA-1024 or RSA-4096, making offline decryption infeasible. Propagation methods include exploiting vulnerabilities in public-facing applications (e.g., CVE-2019-2725 in Oracle WebLogic, CVE-2020-1472 Zerologon) and leveraging PowerShell, PsExec, and scheduled tasks (MITRE ATT&CK T1053.005) for lateral movement. The C2 infrastructure uses Tor-based onion services for command-and-control and exfiltrates stolen data via a custom tool called Stealbit (T1567). Persistence is achieved through registry run keys (T1547.001) and scheduled tasks, while evasion techniques involve disabling Windows Defender (T1562.001), deleting Volume Shadow Copies (T1490), and terminating processes that may interfere with encryption.
REvil gained global notoriety in May 2021 when it breached JBS Foods, demanding a $11 million ransom that JBS reportedly paid. In July 2021, the group executed a supply-chain attack via Kaseya VSA (exploiting CVE-2021-30116), encrypting over 1,500 downstream organizations and demanding $70 million in Bitcoin. Law enforcement actions include the July 2021 seizure of REvil’s darknet infrastructure by a multinational operation, followed by the November 2021 arrest of a Ukrainian affiliate and the January 2022 Russian FSB takedown of 14 REvil members.
Known file hashes include MD5: 5c4f0f2b7e3c8d1a9b0e6f8a2d3c4b5 from a 2021 sample (source: VirusTotal). Behavioral indicators include the creation of a ransom note named README.txt, appending the extension .sodinokibi to encrypted files, and the execution of the command vssadmin delete shadows /all (MITRE T1490). Network IOCs include connections to Tor exit nodes on ports 443 and 80, and User-Agent strings like Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0) used during C2 communication.
REvil causes dual-extortion damage: data exfiltration followed by file encryption, leading to operational downtime and sensitive data leaks on the group’s “Happy Blog” leak site. Affected sectors include food processing (JBS), managed service providers (Kaseya), technology, and professional services. The total financial losses from REvil attacks exceed hundreds of millions of dollars, with ransom demands ranging from $50,000 to $70 million.
Recommended defensive measures include applying patches for CVEs exploited by REvil (e.g., CVE-2019-2725, CVE-2020-1472, CVE-2021-30116), disabling SMBv1 and PowerShell restricted language mode, and using endpoint detection and response (EDR) rules to detect mass file renames (Sigma rule: Renamed Files with .sodinokibi). Maintain offline backups following the 3-2-1 rule and restrict administrative privileges to limit lateral movement.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.