REvil

Last reviewed:

REvil is a sophisticated ransomware strain that has been used in numerous cyberattacks targeting various industries worldwide. Known for its advanced encryption techniques and extortion tactics, REvil has been attributed to several high-profile ransomware incidents. The ransomware is typically deployed through phishing emails, exploit kits, and vulnerable Remote Desktop Protocol (RDP) connections. As of October 2023, cybersecurity organizations continue to monitor and mitigate threats posed by REvil.

Overview

REvil, also known as Sodinokibi, is a ransomware-as-a-service (RaaS) platform. It enables cybercriminals to lease the ransomware to affiliates who then carry out attacks. The ransomware encrypts files on infected systems and demands a ransom payment, typically in cryptocurrency, for the decryption key. REvil is known for its double extortion tactics, where attackers threaten to release stolen data if the ransom is not paid.

History

REvil first emerged in April 2019, quickly gaining notoriety for its effectiveness and the high-profile nature of its attacks. The ransomware is believed to have evolved from the GandCrab ransomware, which ceased operations in early 2019. REvil has been linked to several attacks on large organizations, including those in the healthcare, finance, and technology sectors. In 2021, REvil was involved in a significant attack on a major meat processing company, to widespread disruptions.

Technical characteristics

REvil employs advanced encryption algorithms to lock files on infected systems. It uses a combination of RSA and AES encryption to ensure that files cannot be easily decrypted without the unique decryption key. The ransomware is capable of deleting shadow copies and disabling system recovery features to prevent victims from restoring their data. REvil also features a robust command-and-control (C2) infrastructure, allowing attackers to manage and update the ransomware remotely.

Infection vector

REvil is typically delivered through phishing emails containing malicious attachments or links. These emails often impersonate legitimate organizations or individuals to trick recipients into opening the attachments or clicking the links. Once executed, the ransomware exploits vulnerabilities in the system or uses stolen credentials to gain access. REvil has also been distributed through exploit kits and compromised websites.

Notable campaigns

REvil has been involved in several high-profile ransomware attacks. In 2020, the ransomware targeted a major law firm, resulting in the theft of sensitive celebrity data. In 2021, REvil was responsible for an attack on a global meat processing company, to a temporary shutdown of operations. The ransomware has also targeted managed service providers (MSPs), affecting multiple clients simultaneously.

Detection and mitigation

Detecting REvil requires a combination of signature-based and behavior-based detection methods. Security solutions should be updated regularly to recognize the latest variants of the ransomware. Organizations can mitigate the risk of REvil infections by implementing robust email filtering, conducting regular security awareness training, and ensuring that all software and systems are up to date with the latest security patches. Network segmentation and the use of multi-factor authentication (MFA) can also help prevent the spread of the ransomware within an organization.

REvil Attack Process

History of REvil

Industries Targeted by REvil

See also

  • Lateral movement

Sources

Categories: Malware
Last updated: September 20, 2026