September 22, 2023

Ransomware gang REvil has disappeared following pressure from the U.S. government on Russia to act on ransomware groups operating in the country.

The REvil ransomware gang, also known as Sodinokibi, dates back to 2018 and is believed to be an offshoot of the now-defunct GandCrab ransomware gang. REvil, in its three years, has been prolific in its attacks.

An attack exploiting a vulnerability on Oracle Corp.’s WebLogic Server and has regularly done in 2019 was the first one. Notable REvil ransomware attacks include CyrusOne Inc. in December 2019; Travelex the same month, a notable target as the company subsequently paid the ransom; celebrity law firm Grubman Shire Meiselas & Sacks in May 2020; video games maker Capcom Co. Ltd. in November; U.K. cosmetic surgery provider Transform Hospital Group Ltd. in December; and insurance company CNA Financial Corp. in March.

More recent attacks include REvil demanding a $50 million payment from computer maker Acer Inc., a ransomware attack that resulted in meat processing company JBS S.A. paying an $11 million ransomware payment, and an attack on Taiwanese manufacturer Quanta Computer Inc. that resulted in the theft of Apple Inc. blueprints.

REvil’s ultimate downfall, though, may be its last attack targeting software company Kaseya Ltd. earlier this month. That one drew the attention of the White House.

The White House vowed to take action against Russia if the attack was linked to the country. U.S. President Joe Biden spoke to Russian President Putin when he underscored the need for Russia to disrupt ransomware groups operating in the country.

Whether REvil’s alleged disappearance is the result of Russia acting after the request from the U.S. to crack down on ransomware gangs operating in the country is pure speculation. The Associated Press correctly notes in its headline that the cause isn’t clear but added that there is no sign of a law enforcement takedown.

Ransomware gangs come and go on a regular basis and REvil has been a highly profitable one. Those behind the group could have simply taken their profits and run amid increasing attention.

Ransomware gangs operating in Russia were on borrowed time the second Colonial was hit, The Russian government didn’t care about the cybercrime occurring within its borders, but only so long as it didn’t impact Russia itself.

But that, he added, has clearly changed, and the Russian government can clearly see it’s being hurt by the actions of these hackers. Whether REvil was taken out of commission by the Russian government, saw the writing on the wall and took infrastructure down and is simply rebranding like so many groups have likely including REvil itself or something else is unknown at this point.

Leave a Reply

%d bloggers like this: