TLP:CLEAR
⚠ ECRIME · RUSSIA-BASED RAAS OPERATOR · NO CONFIRMED STATE SPONSORSHIP
// Threat Actor Profile — Ransomware-as-a-Service (RaaS) Operator / Double-Extortion Ransomware

REVIL

PROFILE COMPILED: 2026-08-29  |  SOURCES: MITRE ATT&CK (G0115 GOLD SOUTHFIELD; S0496 REvil), U.S. DOJ, Wikipedia, CFR Cyber Operations Tracker, Lawfare, The Record, Krebs on Security, Trellix, SentinelOne, 8+ additional vendor/press sources
Status: DORMANT SINCE JAN 2022 — CONTESTED, UNCONFIRMED 2022 REEMERGENCE
Threat Level: HIGH (Historical)
Primary Motive: Financial Extortion — Double-Extortion Ransomware
Active Since: April 2019 (assessed successor to GandCrab)
MITRE ATT&CK: G0115 (GOLD SOUTHFIELD)
$200M+
Estimated Total Ransom Revenue Across the Group's Operating Lifetime
1,500
Downstream Businesses Hit by the Single Kaseya VSA Supply-Chain Attack (Jul 2021)
$70M
Ransom Demanded for a Universal Kaseya Decryptor — Never Paid
14
Individuals Arrested by Russia's FSB in the Jan 2022 Takedown
00
Overview

REvil — also tracked as Sodinokibi, and by MITRE ATT&CK under the group designation GOLD SOUTHFIELD (G0115, also known as Pinchy Spider) — was one of the most prolific and financially destructive ransomware-as-a-service (RaaS) operations in cybercrime history, active from April 2019 until a coordinated law-enforcement and diplomatic pressure campaign forced it into apparent dormancy in early 2022. Believed to be a successor to the GandCrab ransomware operation (which "retired" in June 2019 after reportedly earning its developers over $2 billion), REvil refined the double-extortion playbook — encrypting victim data while separately threatening to publish stolen files on its "Happy Blog" leak site — into a repeatable, franchised criminal business model.

Operating as a RaaS platform, REvil's core developers provided ransomware tooling, negotiation infrastructure, and the Happy Blog to a network of affiliates who conducted the actual intrusions and split ransom proceeds with the operators. This model let REvil scale far beyond what a single team could achieve, and its affiliates were responsible for some of the most consequential ransomware attacks of 2020–2021: foreign-exchange firm Travelex ($2.3M paid in early 2020), electronics manufacturer Acer ($50M demanded), and JBS Foods, the world's largest meat processor, which paid $11 million in June 2021 after the attack disrupted North American and Australian meat supply chains.

REvil's defining and most consequential operation came on July 2, 2021, when affiliates exploited a zero-day authentication-bypass and SQL-injection chain (CVE-2021-30116) in Kaseya VSA — remote-monitoring software used by managed service providers (MSPs) — to push ransomware through roughly 50 MSPs to an estimated 800–1,500 downstream small and mid-sized businesses in a single supply-chain attack. REvil demanded $70 million for a universal decryption key; Kaseya obtained a working decryptor from what it called a "trusted third party" without paying, later revealed to be the FBI, which had obtained REvil's decryption keys through a foreign partner's covert access to REvil's own infrastructure.

The Kaseya attack's scale, arriving weeks after the JBS attack and the unrelated but similarly high-profile DarkSide attack on Colonial Pipeline, triggered direct US-Russia diplomatic pressure and a rare law-enforcement response: in October 2021 a multinational operation (FBI, US Cyber Command, Secret Service, and foreign partners) hacked REvil's own servers and forced its leak site and payment portal offline, and in January 2022 Russia's FSB — acting, according to Russian and US officials, at direct US request — raided 25 addresses across Russia and arrested 14 individuals, seizing cash, cryptocurrency, and luxury vehicles. A REvil-branded leak site briefly reappeared in April 2022, but researchers have never conclusively determined whether this reflected genuine reactivation by original operators, a successor group reusing the brand, or something else entirely.

01
Identity & Attribution
Primary NameREvil (also known as Sodinokibi, Sodin)
Sponsor / ParentNone confirmed — independent, financially motivated Russian-speaking criminal enterprise; no verified state sponsorship, though its continued operation from within Russia and the limited scope of its eventual Russian prosecution have drawn analytical scrutiny
Actor TypeeCrime — Ransomware-as-a-Service (RaaS) Operator/Developer
Primary MotivationFinancial extortion via double-extortion ransomware (encryption + data-leak threat)
Active SinceApril 2019; assessed successor to the GandCrab ransomware operation (retired June 2019), sharing core developers per code/tooling similarity
Last ObservedA REvil-branded leak site briefly reappeared online in April 2022; no confirmed, independently verified operations attributed to the original group since the January 2022 Russian arrests
MITRE G-IDG0115 (GOLD SOUTHFIELD, aka Pinchy Spider); malware tracked separately as Software S0496 (REvil)
Legal Status14 individuals arrested by Russia's FSB (Jan 2022) under payment-instrument-fraud statutes, not ransomware/hacking charges specifically; separately, US DOJ indicted Yaroslav Vasinskyi (extradited 2022, sentenced May 2024 to 13 years 7 months and $16M restitution for the Kaseya attack) and Yevgeniy Polyanin (charged for a 2019 Texas-focused campaign, remains at large)
Tracking Aliases
REvil Sodinokibi Sodin GOLD SOUTHFIELD Pinchy Spider
Attribution Confidence

HIGH that REvil operated as a Russian-speaking, financially motivated criminal RaaS enterprise, corroborated by law-enforcement action on both the US and Russian sides and by successful US prosecutions of named affiliates. Confidence is LOW-MEDIUM on whether the group had any form of state tolerance or protection beyond Russia's general historical unwillingness to prosecute ransomware operators targeting foreign victims — the January 2022 arrests were charged under payment-fraud rather than computer-crime statutes, arrived amid intense diplomatic pressure, and have been followed by no publicly disclosed trial outcomes as of this writing.

02
Campaign & Operational Timeline
APR 2019
Emergence as GandCrab's Successor
REvil (Sodinokibi) first appears shortly before the GandCrab RaaS operation "retires" in June 2019; strong code and tooling overlap leads researchers to assess REvil as an evolution of the same core developer team.
AUG 2019
Early Sodinokibi Campaign Against Texas Entities
Affiliates (later linked to Yevgeniy Polyanin) conduct a wave of Sodinokibi ransomware attacks against Texas-based organizations, among the group's first major documented campaigns.
DEC 2019 –
JAN 2020
Travelex Attack
REvil affiliates breach foreign-exchange firm Travelex, demanding $6 million; Travelex reportedly pays $2.3 million for a decryption key after a prolonged outage.
MAR 2021
Acer Extortion Attempt
Exploiting Microsoft Exchange server vulnerabilities, REvil affiliates breach electronics manufacturer Acer and demand $50 million, among the largest ransom demands publicly disclosed to that point.
MAY –
JUN 2021
JBS Foods Attack
REvil affiliates encrypt systems at JBS, the world's largest meat processor, disrupting North American and Australian production; JBS pays an $11 million ransom to avoid further disruption and potential data exposure.
JUL 2021
Kaseya VSA Supply-Chain Attack
Exploiting a zero-day authentication-bypass/SQL-injection chain (CVE-2021-30116) in Kaseya VSA, REvil pushes ransomware through ~50 MSPs to an estimated 800–1,500 downstream businesses in a single coordinated operation, demanding $70 million for a universal decryptor.
OCT 2021 –
APR 2022
Law Enforcement Takedown, FSB Arrests & Contested Reemergence
A multinational law-enforcement operation hacks REvil's own servers and forces its infrastructure offline (Oct 2021); Russia's FSB arrests 14 individuals at US request (Jan 2022); the US indicts and later convicts Kaseya-attack affiliate Yaroslav Vasinskyi (extradited 2022, sentenced 2024); a REvil-branded leak site briefly reappears (Apr 2022) under disputed/unconfirmed operatorship, with no independently verified original-group activity documented since.
03
Attack Lifecycle Ransomware-as-a-Service — separating the platform from the affiliates who used it

As a RaaS operation, REvil's "attack lifecycle" is best understood as two linked processes: the core group's development and maintenance of the ransomware platform, negotiation portal, and Happy Blog leak site, and the largely independent intrusion campaigns run by dozens of affiliates who paid for access and shared a percentage of ransom proceeds with the operators. Affiliate initial-access methods varied widely and included malicious spam campaigns (T1566), exploitation of public-facing applications such as Oracle WebLogic and Microsoft Exchange servers (T1190), abuse of publicly accessible RDP and remote-monitoring/management (RMM) tooling (T1133), and — in the Kaseya case — a direct software supply-chain compromise (T1195.002) that bypassed the need to breach each victim individually.

Once inside a network, affiliates commonly used legitimate remote-management tools like ConnectWise Control to maintain access and take screen captures of victim environments (T1219, T1113) alongside PowerShell for staging and executing further payloads, frequently base64-encoded to evade signature-based detection (T1059.001, T1027.010). Before deploying the REvil/Sodinokibi encryptor itself, affiliates typically disabled security tooling and backup/shadow-copy services, then exfiltrated sensitive data to support the double-extortion threat before triggering encryption — ensuring victims faced both an availability crisis and a confidentiality threat simultaneously.

The Kaseya operation represents the group's most sophisticated and consequential technical achievement: rather than compromising thousands of individual businesses one at a time, affiliates exploited a chain of vulnerabilities in Kaseya's own VSA management software to push the ransomware payload as a disguised, seemingly legitimate software update — directly abusing the trust relationship between an MSP and its downstream customers (T1199) to achieve mass simultaneous impact from a single point of compromise. This "one-to-many" model foreshadowed the software supply-chain risk that has since become a central concern across the ransomware and broader cyber threat landscape.

04
TTPs — MITRE ATT&CK Mapping Enterprise framework; group techniques from G0115, malware behaviors from S0496
Initial Access
T1566
Phishing
[HIGH] Conducted malicious spam (malspam) campaigns to deliver initial-access malware/loaders ahead of REvil deployment.
Initial Access
T1190
Exploit Public-Facing Application
[HIGH] Exploited Oracle WebLogic and Microsoft Exchange vulnerabilities, and later a Kaseya VSA auth-bypass/SQLi chain (CVE-2021-30116), for initial compromise.
Initial Access
T1133
External Remote Services
[MEDIUM] Abused publicly accessible RDP and remote-monitoring/management (RMM) servers as an entry point into victim networks.
Initial Access
T1199
Trusted Relationship
[HIGH] Breached Managed Service Providers (MSPs) to deliver ransomware to downstream MSP customers, most notably in the July 2021 Kaseya VSA attack.
Resource Development
T1195.002
Supply Chain Compromise: Software Supply Chain
[HIGH] Backdoored a legitimate software update mechanism (Kaseya VSA) via strategic web compromise to distribute ransomware at scale to downstream customers.
Execution
T1059.001
Command and Scripting Interpreter: PowerShell
[HIGH] Staged and executed PowerShell scripts on compromised hosts to support payload delivery and execution.
Defense Evasion
T1027.010
Obfuscated Files or Information: Command Obfuscation
[MEDIUM] Executed base64-encoded PowerShell scripts to evade signature-based detection.
Defense Evasion
T1112
Modify Registry
[MEDIUM] Modified Windows Registry settings to disable security features and configure the encryption payload prior to execution.
Collection
T1113
Screen Capture
[LOW] Used the legitimate remote-management tool ConnectWise Control to obtain screen captures from victim machines for reconnaissance.
Command & Control
T1219
Remote Access Tools
[MEDIUM] Used the cloud-based remote-management tool ConnectWise Control to maintain interactive access to compromised environments.
Impact
T1486
Data Encrypted for Impact
[HIGH] Deployed the REvil/Sodinokibi encryptor to encrypt victim files — the core mechanism of the group's double-extortion ransom model.
Impact
T1490
Inhibit System Recovery
[HIGH] Deleted Volume Shadow Copies and disabled backup/recovery mechanisms prior to encryption to prevent victims from restoring data without paying.
05
Targeting Profile
Sector Targeting
Managed Service Providers & IT Services
PRIMARY
Manufacturing & Food/Agriculture
HIGH
Financial Services / Foreign Exchange
MED
Technology / Electronics
MED
Retail & Professional Services (General Affiliate Targeting)
LOW
GeographiesPrimarily United States, with significant impact in Canada, Australia (JBS), and the UK (Travelex); dozens of countries reached indirectly through the Kaseya MSP supply-chain attack. Operators/affiliates assessed predominantly Russian-speaking, based in Russia/former-Soviet states
Victim ProfileLarge enterprises capable of paying seven- or eight-figure ransoms (JBS, Acer, Travelex) alongside opportunistic small and mid-sized businesses reached indirectly through compromised MSPs and software supply chains
Preferred EntryExploitation of internet-facing application vulnerabilities (Exchange, WebLogic, Kaseya VSA), phishing/malspam, and abuse of exposed RDP/RMM tooling — comparatively little reliance on social engineering versus contemporaries like Scattered Spider
Target DoctrineAffiliate-driven and largely opportunistic at the individual-victim level, but RaaS operators actively favored maximum-leverage, high-disruption targets (critical food supply, MSP supply chains) capable of generating outsized ransom payments and media attention
06
Tools, Malware & Infrastructure
REvil / Sodinokibi Encryptor Ransomware / RaaS Payload · MITRE S0496
Core encryption payload distributed to affiliates; encrypts victim files, deletes Volume Shadow Copies, and disables recovery mechanisms before dropping a ransom note directing victims to a Tor-based negotiation portal and threatening publication on the "Happy Blog" leak site if payment is not made.
ConnectWise Control (Abused) Legitimate RMM Tool · Living-off-the-Land
Commercial remote-management/monitoring software abused post-compromise to maintain interactive access, capture victim-machine screenshots, and stage further payloads while blending with legitimate IT administration traffic.
Happy Blog Double-Extortion Leak Site
Tor-hosted data-leak and auction site used to publish or threaten publication of exfiltrated victim data, and in some cases to auction stolen data to third parties, reinforcing the ransom demand with a confidentiality threat independent of encryption.
CVE-2021-30116 Exploit Chain Zero-Day Auth Bypass + SQL Injection
Chained a Kaseya VSA credential-disclosure/authentication-bypass flaw with a SQL-injection vulnerability to gain administrative control of the VSA management console, enabling the July 2021 supply-chain attack that reached an estimated 800–1,500 downstream businesses through a single compromised software vendor.
07
Indicators of Compromise All IPs and domains defanged
⚠ IOC HANDLING — All IPs and domains in this table are defanged. Reconstruct before use in detection tooling. Reference URLs in Section 10 are NOT defanged.
Type Value / Description Source Date
CVECVE-2021-30116 — Kaseya VSA authentication bypass / credential disclosure, chained with SQL injectionKaseya; CISA; SentinelOne2021-07
MALWAREREvil / Sodinokibi ransomware (MITRE Software S0496)MITRE ATT&CK; multiple vendor analyses2019–2022
INFRA"Happy Blog" Tor-hosted leak/auction site — offline since Oct 2021 law-enforcement operation; brief unconfirmed reappearance Apr 2022Multiple press reporting2020–2022
CHARGEDYaroslav Vasinskyi ("Rabotnik"); Yevgeniy PolyaninUS DOJ2021–2024
NOTENo durable, current static IP/domain/hash indicator list is included here — REvil's core infrastructure was seized/dismantled by law enforcement in Oct 2021 and Jan 2022, and any indicators from the group's 2019–2021 operating period are archival. Consult MITRE ATT&CK Software S0496 and named vendor incident reports for the historical technical indicator set.
08
Analyst Assessment
Overall Threat LevelHIGH (Historical) — not confirmed as a currently active, independently operating threat
Attribution ConfidenceHIGH (criminal enterprise) / LOW-MEDIUM (any state tolerance/protection)
TrajectoryAssessed dormant since the Jan 2022 arrests; the contested Apr 2022 brand reemergence was never independently verified, and by 2026 the broader ransomware ecosystem has moved on to other dominant RaaS brands
Most Dangerous Capability (Historical)Converting a single software supply-chain compromise (Kaseya) into simultaneous ransomware deployment across 800–1,500+ independently owned downstream victims
Primary Intel GapWhether original REvil developers or key affiliates remain at large and operating under new group identities; the true durability of the January 2022 Russian enforcement action given the absence of disclosed trial outcomes
Ecosystem / Affiliated Groups
GandCrab (assessed predecessor) DarkSide (founded by suspected former REvil affiliates — NOT the same group; DarkSide, not REvil, conducted the Colonial Pipeline attack)

REvil's historical significance rests less on any single technical innovation than on how completely it operationalized the RaaS business model and the double-extortion playbook that nearly every major ransomware group has since adopted as standard practice. Its Kaseya operation in particular demonstrated, more clearly than any prior incident, that ransomware operators had begun to think in terms of supply-chain leverage rather than single-victim opportunism — a shift with implications for defenders far beyond the ransomware threat specifically.

The January 2022 Russian enforcement action against REvil remains one of the most closely scrutinized instances of Russian cooperation against a cybercriminal group targeting foreign victims, and analysts remain divided on how to interpret it. The charges filed (payment-instrument fraud rather than computer intrusion or extortion) and the absence of any publicly disclosed trial outcomes since the January 2022 arrests are consistent with either a genuine but narrowly scoped prosecution, or a primarily diplomatic gesture timed to reduce US pressure during a period of heightened geopolitical tension — this profile does not have sufficient public evidence to resolve which interpretation is correct.

The brief, unconfirmed reappearance of a REvil-branded leak site in April 2022 and the group's subsequent silence make its current operational status genuinely uncertain rather than confidently closed. Given the RaaS model's core asset is code and affiliate relationships rather than any single individual, the possibility that former REvil developers or senior affiliates continue operating — under a different brand entirely — should be treated as at least as likely as a clean, permanent shutdown of all associated capability and personnel.

09
Defensive Recommendations
01
Patch internet-facing management and remote-access software aggressively. Prioritize patching for VPN, RMM, and IT-management platforms (the Kaseya VSA vulnerability class) on the same urgency tier as internet-facing servers, given their demonstrated one-to-many blast radius.
Counters: T1190, T1195.002
02
Apply zero-trust principles to MSP and vendor access. Segment and monitor the specific access paths MSPs and software vendors use into your environment, and require verification for pushed software updates rather than implicit trust.
Counters: T1199
03
Restrict and monitor RDP and RMM tool exposure. Disable public-facing RDP where possible, enforce MFA and IP allowlisting where it must remain exposed, and treat legitimate RMM tools (e.g., ConnectWise Control) as high-value monitoring targets for anomalous use.
Counters: T1133, T1219, T1113
04
Deploy anti-phishing controls and user training. Maintain sandboxed attachment detonation and DMARC/DKIM/SPF enforcement, since malspam remains a persistent initial-access vector for affiliate-driven RaaS operations.
Counters: T1566
05
Monitor for base64-encoded/obfuscated PowerShell execution. Enable PowerShell script-block logging and alert on encoded-command execution, a documented REvil-affiliate technique for evading signature-based defenses.
Counters: T1059.001, T1027.010
06
Protect Volume Shadow Copies and backups from deletion. Store backups offline/immutable and monitor for vssadmin/wbadmin deletion commands, which reliably precede ransomware detonation.
Counters: T1490
07
Assume double extortion — prioritize exfiltration detection, not just encryption prevention. Deploy DLP and egress monitoring for large or anomalous outbound data transfers, since exfiltration precedes encryption specifically to support leak-site extortion regardless of backup posture.
Counters: General double-extortion posture
08
Maintain a tested incident-response and ransomware negotiation plan before an incident occurs. Given REvil's demonstrated willingness to demand extreme, negotiable amounts, pre-established legal, insurance, and negotiation processes materially affect outcomes.
Counters: General organizational readiness
10
References URLs are NOT defanged — navigate directly