REvil
MITRE ATT&CK: S0496 View on attack.mitre.org
Aliases: Sodin, Sodinokibi, REvil, Revil
- First seen
- 2019-04-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 83 (83 malicious)
- Last IoC activity
- 2026-08-25 23:16:15
- Profile updated
- 2026-07-07 12:39:08
Targeted industries: manufacturing transportation-and-logistics energy-and-utilities
Context
REvil is a ransomware family that has been linked to the GOLD SOUTHFIELD group and operated as ransomware-as-a-service (RaaS) since at least April 2019. REvil, which as been used against organizations in the manufacturing, transportation, and electric sectors, is highly configurable and shares code similarities with the GandCrab RaaS.
Recent IoC activity
84 malicious indicators in Maltiverse are attributed to REvil (S0496). The 20 most recently updated:
Detection coverage
- 7 YARA rules
- 911 Sigma rules
Malware & tools used
- Data Encrypted for Impact (attack-pattern)
- Windows Command Shell (attack-pattern)
- PowerShell (attack-pattern)
- Asymmetric Cryptography (attack-pattern)
- Process Injection (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Modify Registry (attack-pattern)
- Data Destruction (attack-pattern)
- Query Registry (attack-pattern)
- Visual Basic (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Service Stop (attack-pattern)
- System Information Discovery (attack-pattern)
- Native API (attack-pattern)
- Malicious File (attack-pattern)
- Create Process with Token (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- Mutual Exclusion (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Drive-by Compromise (attack-pattern)
- System Service Discovery (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Spearphishing Attachment (attack-pattern)
Used by threat actors
- GOLD SOUTHFIELD (threat-actor)
- FIN7 (threat-actor)
Exploited vulnerabilities
- CVE-2019-2725 (vulnerability)
- CVE-2018-8453 (vulnerability)
Detection rules
- TRELLIX_ARC_Sodinokobi (yara-rule)
- ARKBIRD_SOLG_RAN_ELF_Revil_Jun_2021_1 (yara-rule)
- SEKOIA_Loader_Win_Revil_Loader (yara-rule)
- SIGNATURE_BASE_APT_MAL_Revil_Kaseya_Jul21_1 (yara-rule)
- SIGNATURE_BASE_APT_MAL_Revil_Kaseya_Jul21_2 (yara-rule)
- SIGNATURE_BASE_MAL_RANSOM_Revil_Oct20_1 (yara-rule)
- MALPEDIA_Win_Revil_Auto (yara-rule)
Reports & references
- pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
- CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
- threatintel.blog — Opblueraven Part1 (report)
- CrowdStrike — Double Trouble Ransomware Data Leak Extortion Part 1 (report)
- pwc.co.uk — Cyber Threats 2019 Retrospect (report)
- CrowdStrike — Report2021Gtr (report)
- CrowdStrike — Double Trouble Ransomware Data Leak Extortion Part 2 (report)
- secureworks.com — Gold Southfield (report)
- secureworks.com — Revil Sodinokibi Ransomware (report)
- secureworks.com — Revil The Gandcrab Connection (report)
- Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
- Microsoft — Human Operated Ransomware Attacks A Preventable Disaster (report)
- proofpoint.com — First Step Initial Access Leads Ransomware (report)
- CrowdStrike — The Evolution Of Revil Ransomware And Pinchy Spider (report)
- secureworks.com — Gold Southfield (report)
- CrowdStrike — Carbon Spider Embraces Big Game Hunting Part 1 (report)
- Cisco Talos — Sodinokibi Ransomware Exploits Weblogic (report)
- zdnet.com — Revil Ransomware Group Resurfaces After Brief Hiatus (report)
- macrumors.com — Revil Delists Stolen Apple Schematics Threat (report)
- theverge.com — Ransomware Kaseya Vsa Decryptor Revil (report)
- fsb.ru — Single.Htm%21Id%3D10439388%40Fsbmessage (report)
- analyst1.com — History Of Revil (report)
- angle.ankura.com — Revix Linux Ransomware (report)
- blogs.vmware.com — Esxi Targeting Ransomware The Threats That Are After Your Virtual Machines Part 1 (report)
- cybersecurity.att.com — Revils New Linux Version (report)
External references
- mitre-attack — S0496
- Sodin
- Sodinokibi
- Talos Sodinokibi April 2019
- Secureworks REvil September 2019
- Cylance Sodinokibi July 2019
- Group IB Ransomware May 2020
- G Data Sodinokibi June 2019
- Intel 471 REvil March 2020
- Kaspersky Sodin July 2019
- McAfee Sodinokibi October 2019
- Picus Sodinokibi January 2020
- McAfee REvil October 2019
- Secureworks GandCrab and REvil September 2019
- Tetra Defense Sodinokibi March 2020
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy