REvil

MITRE ATT&CK: S0496 View on attack.mitre.org

Aliases: Sodin, Sodinokibi, REvil, Revil

First seen
2019-04-01 00:00:00
Malware type
ransomware
Family
Malware family
Operating systems
windows
Related IoCs
83 (83 malicious)
Last IoC activity
2026-08-25 23:16:15
Profile updated
2026-07-07 12:39:08

Targeted industries: manufacturing transportation-and-logistics energy-and-utilities

Context

REvil is a ransomware family that has been linked to the GOLD SOUTHFIELD group and operated as ransomware-as-a-service (RaaS) since at least April 2019. REvil, which as been used against organizations in the manufacturing, transportation, and electric sectors, is highly configurable and shares code similarities with the GandCrab RaaS.

Recent IoC activity

84 malicious indicators in Maltiverse are attributed to REvil (S0496). The 20 most recently updated:

TypeIndicatorUpdatedSources
file sample VirusShare_21d01fa87dfcaf971ff7b63a1a6fda94 2026-09-02 3
file sample PORT.bin 2026-08-25 1
file sample 2026-08-23_6f0d52a54558769e96861c3096a607d7_coinminer_elex_revil 2026-08-24 1
file sample 2026-08-23_84f69c5842908b4cc34f367222b93d71_coinminer_elex_revil 2026-08-24 1
file sample 2026-08-23_c0dd00b55874f46896ac2115899c2799_coinminer_elex_revil 2026-08-23 1
file sample 464622890dea3c326440b7d1f6da9f63dd2dfd98678965aa220ed62773a2cc70 2026-08-23 2
file sample 16a893ebca922aa7cac02ec569529a0166c63a760122402a53cdb25f75ec8338 2026-08-21 1
file sample 2026-08-21_1db247810db46e9c457ac2edb9f7df2f_coinminer_elex_revil 2026-08-21 1
file sample 2026-08-21_0ff6be1dcad132eda1488678e3cd8c31_coinminer_elex_revil 2026-08-21 1
file sample 2026-08-21_64c9b5337175bb49b9921581a0655123_coinminer_elex_revil 2026-08-21 1
file sample 2026-08-21_a7c95e370c42b5bc7fdf5e2e39e357c2_coinminer_elex_revil 2026-08-21 1
file sample 2026-08-21_be0817b727ae69b04806fa71fcc42ea6_coinminer_elex_revil 2026-08-21 1
file sample 2026-08-21_f16e024d79733d6b01bdc35262a70a75_coinminer_elex_revil 2026-08-21 1
file sample cea292e0e6bea388c992cc6d3e6306454c35b01a6e0546e1ccd64962126eb723 2026-08-14 1
file sample b174334aaffec65fc8ec20be05f06fd8cfe079094a3c828e8b76b590abf2bc43 2026-08-12 1
file sample e9e97f95390ccda6101cd90657acf40e45373733272e01cdd1e57916ee50f8cc 2026-08-12 1
file sample 52ca55d12b8587d2d5cbc99588ef45ff983ef68009a9d49b01d01605cdca7387 2026-08-12 1
file sample 2c5bb7122231abee264ce69ac9b95274f13f29bc1452872932126ac3bac46557 2026-08-12 1
file sample c8f2e4658b0ea21b84831ad110708cee0b6cf3f24782d131bfe54c9f3ed4f32d 2026-08-12 1
file sample 38c8c256c523ceaf654f8fe7854720a9b73001ccec9109dd66ed6b98f81120bb 2026-08-12 1

Detection coverage

  • 7 YARA rules
  • 911 Sigma rules

Malware & tools used

  • Data Encrypted for Impact (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • PowerShell (attack-pattern)
  • Asymmetric Cryptography (attack-pattern)
  • Process Injection (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Modify Registry (attack-pattern)
  • Data Destruction (attack-pattern)
  • Query Registry (attack-pattern)
  • Visual Basic (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Service Stop (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Native API (attack-pattern)
  • Malicious File (attack-pattern)
  • Create Process with Token (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Mutual Exclusion (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Drive-by Compromise (attack-pattern)
  • System Service Discovery (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Spearphishing Attachment (attack-pattern)

Used by threat actors

Exploited vulnerabilities

  • CVE-2019-2725 (vulnerability)
  • CVE-2018-8453 (vulnerability)

Detection rules

  • TRELLIX_ARC_Sodinokobi (yara-rule)
  • ARKBIRD_SOLG_RAN_ELF_Revil_Jun_2021_1 (yara-rule)
  • SEKOIA_Loader_Win_Revil_Loader (yara-rule)
  • SIGNATURE_BASE_APT_MAL_Revil_Kaseya_Jul21_1 (yara-rule)
  • SIGNATURE_BASE_APT_MAL_Revil_Kaseya_Jul21_2 (yara-rule)
  • SIGNATURE_BASE_MAL_RANSOM_Revil_Oct20_1 (yara-rule)
  • MALPEDIA_Win_Revil_Auto (yara-rule)

Reports & references

  • pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
  • CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
  • threatintel.blog — Opblueraven Part1 (report)
  • CrowdStrike — Double Trouble Ransomware Data Leak Extortion Part 1 (report)
  • pwc.co.uk — Cyber Threats 2019 Retrospect (report)
  • CrowdStrike — Report2021Gtr (report)
  • CrowdStrike — Double Trouble Ransomware Data Leak Extortion Part 2 (report)
  • secureworks.com — Gold Southfield (report)
  • secureworks.com — Revil Sodinokibi Ransomware (report)
  • secureworks.com — Revil The Gandcrab Connection (report)
  • Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
  • Microsoft — Human Operated Ransomware Attacks A Preventable Disaster (report)
  • proofpoint.com — First Step Initial Access Leads Ransomware (report)
  • CrowdStrike — The Evolution Of Revil Ransomware And Pinchy Spider (report)
  • secureworks.com — Gold Southfield (report)
  • CrowdStrike — Carbon Spider Embraces Big Game Hunting Part 1 (report)
  • Cisco Talos — Sodinokibi Ransomware Exploits Weblogic (report)
  • zdnet.com — Revil Ransomware Group Resurfaces After Brief Hiatus (report)
  • macrumors.com — Revil Delists Stolen Apple Schematics Threat (report)
  • theverge.com — Ransomware Kaseya Vsa Decryptor Revil (report)
  • fsb.ru — Single.Htm%21Id%3D10439388%40Fsbmessage (report)
  • analyst1.com — History Of Revil (report)
  • angle.ankura.com — Revix Linux Ransomware (report)
  • blogs.vmware.com — Esxi Targeting Ransomware The Threats That Are After Your Virtual Machines Part 1 (report)
  • cybersecurity.att.com — Revils New Linux Version (report)

External references