Sodinokibi ransomware group also known as REvil (Ransomware Evil) operates as a ransomware-as-a-service (RaaS) model. After the group compromised his victims, they would threaten to publish the victim's sensitive data on their darknet blog named 'Happy Blog', unless the ransom is paid. The ransomware malware code used by REvil is pretty similar to the ransomware code used by DarkSide - a different threat actor. REvil group claims to steal information after a successful attack on the supplier of the tech giant Apple and stole confidential schematics of their upcoming products. Known victims: 96 20 negotiation log(s) available, 3 ransom note(s) on file
Objectives
Executive Summary
REvil (also known as Sodinokibi) is a medium-sophistication criminal threat actor specializing in ransomware operations. They operate under a ransomware-as-a-service (RaaS) model, targeting primarily financial and technology sectors globally since their first appearance in August 2019. REvil is notorious for its double extortion tactics—encrypting victim data and threatening to publish stolen information on their darknet blog unless a ransom is paid.
Goals & Targeting
REvil's primary strategic objective is financial gain through the deployment of ransomware and the threat of data exposure. They target organizations across various sectors where sensitive data holds significant value or where disruption could lead to substantial financial losses. Their focus on double extortion aligns with maximizing profits, as victims may feel pressured to pay ransoms to avoid reputational damage and legal consequences associated with data breaches. REvil's operational targeting appears to be geographically agnostic, with a history of victimizing entities worldwide.
Enhanced Description
REvil, or Sodinokibi, is a prominent ransomware group that operates under the Ransomware-as-a-Service (RaaS) model. The group primarily targets businesses across various sectors, including technology, manufacturing, and healthcare. REvil's operations are characterized by their double extortion tactic: they both encrypt victims' data and threaten to release stolen information on their darknet blog unless a ransom is paid in cryptocurrency. Unlike many other ransomware groups, REvil has avoided targeting critical infrastructure, focusing instead on corporate environments with potentially high-value data. The group's malware shares similarities with the DarkSide ransomware, though it maintains distinct operational characteristics. REvil has targeted high-profile victims, including the supplier of Apple Inc., from which they stole confidential schematics of upcoming products. Their campaign patterns typically involve initial access through phishing or compromising third-party vendors, followed by lateral movement within the network to identify and exfiltrate sensitive data before deploying the ransomware payload.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
REvil has been active since August 2019 and is known for high-profile attacks, including the compromise of Apple's supplier. Their campaigns often involve targeted phishing or third-party vendor exploitation to gain initial access. Once inside a network, REvil establishes persistence, moves laterally, collects sensitive data, and deploys ransomware. Negotiation logs indicate that the group typically demands substantial ransoms in cryptocurrency and has demonstrated patience in waiting for victims to comply. Notable campaigns include attacks against financial institutions and technology providers, leveraging their double extortion model to maximize financial gain.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The intelligence on REvil is moderately high, given their consistent operational presence and media coverage of their campaigns. However, certain aspects, such as the exact toolset used for initial access and the full scope of their infection chain, remain less clear due to limited visibility into their internal operations.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics