Description
REvil (a.k.a. Sodinokibi) is a ransomware as a service operation that was highly active until 2021 and conducted extortion campaigns that set industry records. Its affiliates breached organizations through software supply chain compromises and vulnerabilities, exfiltrated data, and demanded record ransoms, including payments in the tens of millions of dollars. International law enforcement pressure, arrests, and infrastructure seizures eventually dismantled the brand, though its members continue in successor operations.
Stats
- First seen
- January 2022
- Last seen
- October 2026
Also known as
RevilSodinokibi
MITRE ATT&CK techniques
35 techniques across 8 tactics.
TA0002 Execution
TA0005 Stealth
TA0007 Discovery
TA0011 Command and Control
TA0010 Exfiltration
- T1041Exfiltration Over C2 Channel
TA0040 Impact
Associated groups
Alert name variants
| Alert Name |
|---|
| ByteCode-MSIL.Ransomware.REvil |
| DeepScan:Generic.Ransom.Sodinokibi.8F2E42A9 |
| Dump:Generic.Ransom.Sodinokibi.57996BEB |
| Dump:Generic.Ransom.Sodinokibi.6DF64567 |
| Dump:Generic.Ransom.Sodinokibi.8F2E42A9 |
| Gen:Variant.Ransom.Sodinokibi.116 |
| Gen:Variant.Ransom.Sodinokibi.165 |
| Gen:Variant.Ransom.Sodinokibi.205 |
| Gen:Variant.Ransom.Sodinokibi.334 |
| Gen:Variant.Ransom.Sodinokibi.341 |








