Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Description

Sodinokibi ransomware group also known as REvil (Ransomware Evil) operates as a ransomware-as-a-service (RaaS) model. After the group compromised his victims, they would threaten to publish the victim's sensitive data on their darknet blog named 'Happy Blog', unless the ransom is paid. The ransomware malware code used by REvil is pretty similar to the ransomware code used by DarkSide - a different threat actor. REvil group claims to steal information after a successful attack on the supplier of the tech giant Apple and stole confidential schematics of their upcoming products. Known victims: 96 20 negotiation log(s) available, 3 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

REvil (also known as Sodinokibi) is a medium-sophistication criminal threat actor specializing in ransomware operations. They operate under a ransomware-as-a-service (RaaS) model, targeting primarily financial and technology sectors globally since their first appearance in August 2019. REvil is notorious for its double extortion tactics—encrypting victim data and threatening to publish stolen information on their darknet blog unless a ransom is paid.

Goals & Targeting

REvil's primary strategic objective is financial gain through the deployment of ransomware and the threat of data exposure. They target organizations across various sectors where sensitive data holds significant value or where disruption could lead to substantial financial losses. Their focus on double extortion aligns with maximizing profits, as victims may feel pressured to pay ransoms to avoid reputational damage and legal consequences associated with data breaches. REvil's operational targeting appears to be geographically agnostic, with a history of victimizing entities worldwide.

Enhanced Description

REvil, or Sodinokibi, is a prominent ransomware group that operates under the Ransomware-as-a-Service (RaaS) model. The group primarily targets businesses across various sectors, including technology, manufacturing, and healthcare. REvil's operations are characterized by their double extortion tactic: they both encrypt victims' data and threaten to release stolen information on their darknet blog unless a ransom is paid in cryptocurrency. Unlike many other ransomware groups, REvil has avoided targeting critical infrastructure, focusing instead on corporate environments with potentially high-value data. The group's malware shares similarities with the DarkSide ransomware, though it maintains distinct operational characteristics. REvil has targeted high-profile victims, including the supplier of Apple Inc., from which they stole confidential schematics of upcoming products. Their campaign patterns typically involve initial access through phishing or compromising third-party vendors, followed by lateral movement within the network to identify and exfiltrate sensitive data before deploying the ransomware payload.

Key Capabilities

  • Ransomware deployment
  • Double extortion tactics (encrypting data and threatening data leakage)
  • Use of a Ransomware-as-a-Service (RaaS) model
  • Network infiltration and lateral movement
  • Data exfiltration for blackmail purposes

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Defense Evasion

ATT&CK Techniques

T1059
T1204
T1566
T1055

Software / Tooling

Sodinokibi Ransomware
Cobalt Strike (potentially for initial access)

Campaigns & Victims

REvil has been active since August 2019 and is known for high-profile attacks, including the compromise of Apple's supplier. Their campaigns often involve targeted phishing or third-party vendor exploitation to gain initial access. Once inside a network, REvil establishes persistence, moves laterally, collects sensitive data, and deploys ransomware. Negotiation logs indicate that the group typically demands substantial ransoms in cryptocurrency and has demonstrated patience in waiting for victims to comply. Notable campaigns include attacks against financial institutions and technology providers, leveraging their double extortion model to maximize financial gain.

IOC Patterns

  • Spear-phishing emails with malicious links or attachments
  • Ransomware encryption on networked devices and servers
  • Exfiltration of sensitive data prior to ransomware deployment
  • Threats of data publication on a darknet blog ('Happy Blog')
  • Use of domain fronting for command-and-control (C2) communication

Recommended Actions

  • Implement advanced email filtering solutions to detect phishing attempts
  • Conduct regular network monitoring for suspicious lateral movement patterns
  • Enhance endpoint detection and response capabilities to identify ransomware activity early
  • Encrypt sensitive data at rest and ensure backups are air-gapped
  • Establish incident response playbooks for dealing with double extortion attacks

Suggested Tags

Ransomware
Double extortion
Financial gain
Cybercriminal

Confidence Assessment

The intelligence on REvil is moderately high, given their consistent operational presence and media coverage of their campaigns. However, certain aspects, such as the exact toolset used for initial access and the full scope of their infection chain, remain less clear due to limited visibility into their internal operations.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Critical Infrastructure
Data Exfiltration
Double extortion
Financial gain
Cybercriminal

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Aug 26, 2019
Last Seen
Nov 28, 2022
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.