REvil — also tracked as Sodinokibi, and by MITRE ATT&CK under the group designation GOLD SOUTHFIELD (G0115, also known as Pinchy Spider) — was one of the most prolific and financially destructive ransomware-as-a-service (RaaS) operations in cybercrime history, active from April 2019 until a coordinated law-enforcement and diplomatic pressure campaign forced it into apparent dormancy in early 2022. Believed to be a successor to the GandCrab ransomware operation (which "retired" in June 2019 after reportedly earning its developers over $2 billion), REvil refined the double-extortion playbook — encrypting victim data while separately threatening to publish stolen files on its "Happy Blog" leak site — into a repeatable, franchised criminal business model.
Operating as a RaaS platform, REvil's core developers provided ransomware tooling, negotiation infrastructure, and the Happy Blog to a network of affiliates who conducted the actual intrusions and split ransom proceeds with the operators. This model let REvil scale far beyond what a single team could achieve, and its affiliates were responsible for some of the most consequential ransomware attacks of 2020–2021: foreign-exchange firm Travelex ($2.3M paid in early 2020), electronics manufacturer Acer ($50M demanded), and JBS Foods, the world's largest meat processor, which paid $11 million in June 2021 after the attack disrupted North American and Australian meat supply chains.
REvil's defining and most consequential operation came on July 2, 2021, when affiliates exploited a zero-day authentication-bypass and SQL-injection chain (CVE-2021-30116) in Kaseya VSA — remote-monitoring software used by managed service providers (MSPs) — to push ransomware through roughly 50 MSPs to an estimated 800–1,500 downstream small and mid-sized businesses in a single supply-chain attack. REvil demanded $70 million for a universal decryption key; Kaseya obtained a working decryptor from what it called a "trusted third party" without paying, later revealed to be the FBI, which had obtained REvil's decryption keys through a foreign partner's covert access to REvil's own infrastructure.
The Kaseya attack's scale, arriving weeks after the JBS attack and the unrelated but similarly high-profile DarkSide attack on Colonial Pipeline, triggered direct US-Russia diplomatic pressure and a rare law-enforcement response: in October 2021 a multinational operation (FBI, US Cyber Command, Secret Service, and foreign partners) hacked REvil's own servers and forced its leak site and payment portal offline, and in January 2022 Russia's FSB — acting, according to Russian and US officials, at direct US request — raided 25 addresses across Russia and arrested 14 individuals, seizing cash, cryptocurrency, and luxury vehicles. A REvil-branded leak site briefly reappeared in April 2022, but researchers have never conclusively determined whether this reflected genuine reactivation by original operators, a successor group reusing the brand, or something else entirely.
HIGH that REvil operated as a Russian-speaking, financially motivated criminal RaaS enterprise, corroborated by law-enforcement action on both the US and Russian sides and by successful US prosecutions of named affiliates. Confidence is LOW-MEDIUM on whether the group had any form of state tolerance or protection beyond Russia's general historical unwillingness to prosecute ransomware operators targeting foreign victims — the January 2022 arrests were charged under payment-fraud rather than computer-crime statutes, arrived amid intense diplomatic pressure, and have been followed by no publicly disclosed trial outcomes as of this writing.
As a RaaS operation, REvil's "attack lifecycle" is best understood as two linked processes: the core group's development and maintenance of the ransomware platform, negotiation portal, and Happy Blog leak site, and the largely independent intrusion campaigns run by dozens of affiliates who paid for access and shared a percentage of ransom proceeds with the operators. Affiliate initial-access methods varied widely and included malicious spam campaigns (T1566), exploitation of public-facing applications such as Oracle WebLogic and Microsoft Exchange servers (T1190), abuse of publicly accessible RDP and remote-monitoring/management (RMM) tooling (T1133), and — in the Kaseya case — a direct software supply-chain compromise (T1195.002) that bypassed the need to breach each victim individually.
Once inside a network, affiliates commonly used legitimate remote-management tools like ConnectWise Control to maintain access and take screen captures of victim environments (T1219, T1113) alongside PowerShell for staging and executing further payloads, frequently base64-encoded to evade signature-based detection (T1059.001, T1027.010). Before deploying the REvil/Sodinokibi encryptor itself, affiliates typically disabled security tooling and backup/shadow-copy services, then exfiltrated sensitive data to support the double-extortion threat before triggering encryption — ensuring victims faced both an availability crisis and a confidentiality threat simultaneously.
The Kaseya operation represents the group's most sophisticated and consequential technical achievement: rather than compromising thousands of individual businesses one at a time, affiliates exploited a chain of vulnerabilities in Kaseya's own VSA management software to push the ransomware payload as a disguised, seemingly legitimate software update — directly abusing the trust relationship between an MSP and its downstream customers (T1199) to achieve mass simultaneous impact from a single point of compromise. This "one-to-many" model foreshadowed the software supply-chain risk that has since become a central concern across the ransomware and broader cyber threat landscape.
| Type | Value / Description | Source | Date |
|---|---|---|---|
| CVE | CVE-2021-30116 — Kaseya VSA authentication bypass / credential disclosure, chained with SQL injection | Kaseya; CISA; SentinelOne | 2021-07 |
| MALWARE | REvil / Sodinokibi ransomware (MITRE Software S0496) | MITRE ATT&CK; multiple vendor analyses | 2019–2022 |
| INFRA | "Happy Blog" Tor-hosted leak/auction site — offline since Oct 2021 law-enforcement operation; brief unconfirmed reappearance Apr 2022 | Multiple press reporting | 2020–2022 |
| CHARGED | Yaroslav Vasinskyi ("Rabotnik"); Yevgeniy Polyanin | US DOJ | 2021–2024 |
| NOTE | No durable, current static IP/domain/hash indicator list is included here — REvil's core infrastructure was seized/dismantled by law enforcement in Oct 2021 and Jan 2022, and any indicators from the group's 2019–2021 operating period are archival. Consult MITRE ATT&CK Software S0496 and named vendor incident reports for the historical technical indicator set. | ||
REvil's historical significance rests less on any single technical innovation than on how completely it operationalized the RaaS business model and the double-extortion playbook that nearly every major ransomware group has since adopted as standard practice. Its Kaseya operation in particular demonstrated, more clearly than any prior incident, that ransomware operators had begun to think in terms of supply-chain leverage rather than single-victim opportunism — a shift with implications for defenders far beyond the ransomware threat specifically.
The January 2022 Russian enforcement action against REvil remains one of the most closely scrutinized instances of Russian cooperation against a cybercriminal group targeting foreign victims, and analysts remain divided on how to interpret it. The charges filed (payment-instrument fraud rather than computer intrusion or extortion) and the absence of any publicly disclosed trial outcomes since the January 2022 arrests are consistent with either a genuine but narrowly scoped prosecution, or a primarily diplomatic gesture timed to reduce US pressure during a period of heightened geopolitical tension — this profile does not have sufficient public evidence to resolve which interpretation is correct.
The brief, unconfirmed reappearance of a REvil-branded leak site in April 2022 and the group's subsequent silence make its current operational status genuinely uncertain rather than confidently closed. Given the RaaS model's core asset is code and affiliate relationships rather than any single individual, the possibility that former REvil developers or senior affiliates continue operating — under a different brand entirely — should be treated as at least as likely as a clean, permanent shutdown of all associated capability and personnel.