REvil (Ransomware Evil; also known as Sodinokibi) was a Russia-based[1] or Russian-speaking[2] private ransomware-as-a-service (RaaS) operation.[3] After an attack, REvil would threaten to publish the information on their page Happy Blog unless the ransom was received. In a high profile case, REvil attacked a supplier of the tech giant Apple and stole confidential schematics of their upcoming products. In January 2022, the Russian Federal Security Service said they had dismantled REvil and charged several of its members.
History
REvil recruits affiliates to distribute the ransomware for them. As part of this arrangement, the affiliates and ransomware developers split revenue generated from ransom payments.[4] It is difficult to pinpoint their exact location, but they are thought to be based in Russia due to the fact that the group does not target Russian organizations, or those in former Soviet-bloc countries.[5]
Ransomware code used by REvil resembles the code used by DarkSide, a different hacking group; REvil's code is not publicly available, suggesting that DarkSide is an offshoot of REvil[6] or a partner of REvil.[7] REvil and DarkSide use similarly structured ransom notes and the same code to check that the victim is not located in a Commonwealth of Independent States (CIS) country.[8]
Cybersecurity experts believe REvil is an offshoot from a previous notorious, but now-defunct hacker gang, GandCrab.[9] This is suspected due to the fact that REvil first became active directly after GandCrab shutdown, and that the ransomware both share a significant amount of code.
2020
May
As part of the criminal cybergang's operations, they are known for stealing nearly one terabyte of information from the law firm Grubman Shire Meiselas & Sacks and demanding a ransom to not publish it.[10][11][12] The group had attempted to extort other companies and public figures as well.
In May 2020 they demanded $42 million from US president Donald Trump.[13][14] The group claimed to have done this by deciphering the elliptic-curve cryptography that the firm used to protect its data.[15] According to an interview with an alleged member, they found a buyer for Trump information, but this cannot be confirmed.[16] In the same interview, the member claimed that they would bring in $100 million ransoms in 2020.
On 16 May 2020, the group released legal documents totaling a size of 2.4 GB related to the singer Lady Gaga.[17] The following day, they released 169 "harmless" e-mails which referred to Donald Trump or contained the word 'trump'.[11]
They were planning on selling Madonna's information,[18] but eventually reneged.[19]
2021
March
On 27 March 2021, REvil attacked Harris Federation and published multiple financial documents of the federation to its blog. As a result, the IT systems of the federation were shut down for some weeks, affecting up to 37,000 students.[20]
On 18 March 2021, an REvil affiliate claimed on their data leak site that they had downloaded data from multinational hardware and electronics corporation Acer, as well as installing ransomware, which has been linked to the 2021 Microsoft Exchange Server data breach by cybersecurity firm Advanced Intel, which found first signs of Acer servers being targeted from 5 March 2021. A US$50 million ransom was demanded to decrypt the undisclosed number of systems and for the downloaded files to be deleted, increasing to US$100 million if not paid by 28 March 2021.[21]
April
In April 2021, REvil stole plans for upcoming Apple products from Quanta Computer, including purported plans for Apple laptops and an Apple Watch. REvil threatened to release the plans publicly unless they receive $50 million.[22][23]
On 30 May 2021, JBS S.A. was attacked by ransomware which forced the temporary shutdown of all the company’s U.S. beef plants and disrupted operations at poultry and pork plants. A few days later, the White House announced that REvil may be responsible for the JBS S.A. cyberattack. The FBI confirmed the connection in a follow-up statement on Twitter.[24] JBS paid an $11 million ransom in Bitcoin to REvil.
June
On 11 June 2021, Invenergy reported that they were attacked by ransomware. Later, REvil claimed to be responsible.[25]
On 2 July 2021, hundreds of managed service providers had REvil ransomware dropped on their systems through Kaseya desktop management software.[26] REvil demanded $70 million to restore encrypted data.[27] As a consequence the Swedish Coop grocery store chain was forced to close 800 stores during several days.[28][29]
On 7 July 2021, REvil hacked the computers of Florida-based space and weapon-launch technology contractor HX5, which counts the Army, Navy, Air Force, and NASA among its clients, publicly releasing stolen documents on its Happy Blog. The New York Times judged the documents to not be of "vital consequence".[30]
After a July 9 phone call between United States president Joe Biden and Russian president Vladimir Putin, Biden told the press, "I made it very clear to him that the United States expects when a ransomware operation is coming from his soil even though it’s not sponsored by the state, we expect them to act if we give them enough information to act on who that is." Biden later added that the United States would take the group's servers down if Putin did not.[31][32]
On 13 July 2021, REvil websites and other infrastructure vanished from the internet.[33]Politico cited an unnamed senior administration official as stating that "we don't know exactly why they've [REvil] stood down;" the official also did not discount the possibility that Russia shut down the group or forced it to shut down.[34]
On 23 July 2021, Kaseya announced it had received the decryption key for the files encrypted in the July 2 Kaseya VSA ransomware attack from an unnamed "trusted third party", later discovered to be the FBI who had withheld the key for three weeks, and was helping victims restore their files.[35] The key was withheld to avoid tipping off REvil of an FBI effort to take down their servers, which ultimately proved unnecessary after the hackers went offline without intervention.[36]
September
In September 2021, Romanian cybersecurity firm Bitdefender published a free universal decryptor utility to help victims of the REvil/Sodinokibi ransomware recover their encrypted files, if they were encrypted before July 13, 2021.[37] From September until early November, the decryptor was used by more than 1,400 companies to avoid paying over $550 million in ransom and allow them to recover their files.[38]
On 22 September 2021, malware researchers identified a backdoor built into REvil malware that allowed the original gang members to conduct double-chats and cheat their affiliates out of any ransomware payments.[39] Ransomware affiliates who were cheated reportedly posted their claims on a "Hacker's Court", undermining trust in REvil by affiliates. Newer versions of REvil malware reportedly had the backdoor removed.[40]
October
On 21 October 2021, REvil servers were hacked in a multi-country operation and forced offline. VMWare's head of cybersecurity strategy said "The FBI, in conjunction with Cyber Command, the Secret Service and like-minded countries, have truly engaged in significant disruptive actions against these groups,”. A REvil gang member attempted to restore their servers from backups that had also been compromised.[41]
Investigations and criminal charges
As part of Operation GoldDust involving 17 countries, Europol, Eurojust and INTERPOL, law enforcement authorities arrested five individuals tied to Sodinokibi/REvil and two suspects connected to GandCrab ransomware. They are allegedly responsible for 5000 infections, and collected half a million euros in ransomware payments.[42]
On 8 November 2021, the United States Department of Justice unsealed indictments against Ukrainian national Yaroslav Vasinskyi and Russian national Yevgeniy Polyanin. Vasinskyi was charged with conducting ransomware attacks against multiple victims including Kaseya, and was arrested in Poland on 8 October. Polyanin was charged with conducting ransomware attacks against multiple victims including Texas businesses and government entities. The Department worked with the National Police of Ukraine for the charges, and also announced the seizure of $6.1 million tied to ransomware payments. If convicted on all charges, Vasinskyi faces a maximum penalty of 115 years in prison, and Polyanin 145 years in prison.[43]
In January 2022, the Russian Federal Security Service said they had dismantled REvil and charged several of its members after being provided information by the US.[44]
The Fluffy
There is a hacker group called Fluffy with Headquarters in Corrèze, known to have an affiliation with REvil, that primarily uses typosquatting, cybersquatting and keyword stuffing. This hacker group has distributed Magniber ransomware, Sodinokibi, and GandCrab, BlueCrab (It is the next version of GandCrab is the same variant that was used in the Kaseya VSA ransomware attack[45]). In France, it is known as Fluffy,[46] in Germany as Talentfrei,[47] in Australia and English speaking countries as "Emma Hill",[48] and in South Korea as Nebomi (meaning "Four Seasons Blossom" in Korean). Fluffy is known to have claimed a number of victims, especially in South Korea.[49][50]
The campaign in which Fluffy first targeted South Korea is known as Magniber,[51] and it utilized an exploit kit before the emergence of various modified payloads. The techniques employed by these modified payloads vary, but they share a commonality in utilizing standardized technologies supported by web browsers or operating systems, such as URI scheme and BASE64, unlike exploit kits that leverage zero-day vulnerabilities. Users receive security warnings from their operating systems before executing the files; however, the information provided by the attackers is often sufficient for users to decide to disregard the security alerts.
Following the introduction of these altered payloads in South Korea, Fluffy immediately referred to themselves as Nebomi and continued with ransomware attacks. The Seoul Central District Prosecutors' Office announced in November 2023 that accomplices assisting them in South Korea were prosecuted. According to the announcement, during the process of investigating the suspects, records of funds being transferred to Lazarus Group were also discovered.[52] It is unclear whether it is related to the ongoing ransomware investigation, but according to a media report in December 2023, The Supreme Court of Korea claimed that it experienced a cyberattack by the Lazarus Group, resulting in the leakage of sensitive data.[53]
Fluffy is presumed to assist in the distribution of various types of ransomware, ranging from Magniber and REvil to LockBit, leveraging successful cases of watering hole attacks they have executed. For example, it is believed that they may be implicated in incidents such as the successful cyber attack on Toshiba's French branch in May 2021, the claimed cyber attack on the Doosan Group in August 2022, and the claimed cyber attack on the National Tax Service (South Korea) in March 2023.[54]
At times, they employed relatively simple methods, such as emails, for the distribution of REvil ransomware (also known as GandCrab). The content of these emails typically involved impersonating law enforcement agencies. The senders of these emails were two individuals under the age of 19, who claimed to have committed such crimes in response to a proposition that said, "If you join in sending ransomware, we'll share the profits." In the trial held at the Seoul Central District Court in August 2021, they were sentenced to 2 years and 1 year 6 months of imprisonment. One of them had already received a 10-year prison sentence for participating in another campaign.
Angkatan Udara ChiliFuerza Aérea de ChileLambang Angkatan Udara ChiliDibentuk21 Maret 1930; 93 tahun lalu (1930-03-21)Negara ChiliTipe unitAngkatan udaraPeranPeperangan udaraBagian dariAngkatan Bersenjata Chili Angkatan Udara Chili (Spanyol: Fuerza Aérea de Chile, FACHcode: es is deprecated ) adalah angkatan udara dari Chili, sebuah cabang dari militer Chili. Angkatan Udara Chili menyelenggarakan latihan gabungan Salitre dengan negara-negara sahabat lainnya. Angkatan Udara Chili j...
Ini adalah nama Korea; marganya adalah Kim. Kim Hyang-giKim Hyang-gi saat pembacaan naskah Poong, Psikiater Joseon pada tahun 2022Lahir9 Agustus 2000 (umur 23)Yongin, Gyeonggi-do, Korea SelatanPendidikanUniversitas Hanyang[1]PekerjaanAktrisTahun aktif2003-sekarangAgenJikim Entertainment [2]Nama KoreaHangul김향기 Hanja金香起 Alih AksaraGim Hyang-giMcCune–ReischauerKim Hyangki Kim Hyang-gi (Hangul: 김향기; lahir 9 Agustus 2000) adalah seorang aktris...
Artikel ini sebatang kara, artinya tidak ada artikel lain yang memiliki pranala balik ke halaman ini.Bantulah menambah pranala ke artikel ini dari artikel yang berhubungan atau coba peralatan pencari pranala.Tag ini diberikan pada Desember 2023. Untuk orang lain dengan nama yang sama, lihat Mohammad Saleh. Mohammad SalehLahir23 April 1946 (umur 77) Pamekasan, Jawa TimurKebangsaan IndonesiaPekerjaanHakim Agung Indonesia Prof. Dr. H. Mohammad Saleh, SH, MH. (lahir 23 April 1946) adalah Wak...
هذه المقالة يتيمة إذ تصل إليها مقالات أخرى قليلة جدًا. فضلًا، ساعد بإضافة وصلة إليها في مقالات متعلقة بها. (سبتمبر 2018) ميا مارتيني معلومات شخصية اسم الولادة (بالإيطالية: Domenica Rita Adriana Bertè) الميلاد 20 سبتمبر 1947 بانيارا كالابرا الوفاة 12 مايو 1995 (47 سنة) كاردانو آل كا...
Overview of road signs in Greece This article's factual accuracy may be compromised due to out-of-date information. The reason given is: many signs are missing, vastly incomplete. Please help update this article to reflect recent events or newly available information. (May 2018) Greek road signs P-2, P-28 and П-21 in Pefki, Attica. Road signs in Greece are regulated by the Ministry of Transport and the Hellenic Traffic Police, according to the Greek Highway Code. Signs follow the general Eur...
Town in Crimea City in Autonomous Republic of Crimea, UkraineSudak СудакSudaqCitySudak Coat of armsSudakLocation of Sudak (red dot) within CrimeaShow map of CrimeaSudakLocation of Sudak within UkraineShow map of UkraineSudakLocation of Sudak within the Black Sea RegionShow map of Black SeaCoordinates: 44°51′5″N 34°58′21″E / 44.85139°N 34.97250°E / 44.85139; 34.97250Country (de jure) UkraineRepublic (de jure) Autonomous Republic of CrimeaCountry (de fac...
Place in Northern, IsraelNa'uraNa'uraShow map of Northeast IsraelNa'uraShow map of IsraelCoordinates: 32°36′52″N 35°23′28″E / 32.61444°N 35.39111°E / 32.61444; 35.39111Grid position187/224 PALCountry IsraelDistrictNorthernCouncilGilboaPopulation (2022)[1]2,421 Na'ura (Arabic: ناعورة, Hebrew: נָעוּרָה) is an Arab village located in northern Israel. Located to the east of Afula, it falls under the jurisdiction of the Gilbo...
Venezuelan lawyer, politician, and writer (1772–1829) Cristóbal MendozaPortrait by Juan Lovera1st President of the First Republic of VenezuelaIn office5 March 1811 – 21 March 1812Preceded byOffice established; Francisco Tomás Morales as Captain General of VenezuelaSucceeded byFrancisco Espejo Personal detailsBornJosé Cristóbal Hurtado de Mendoza y Montilla(1772-06-23)23 June 1772Trujillo, Viceroyalty of New Granada, Spanish EmpireDied8 February 1829(1829-02-08) (aged 56)...
Extinct indigenous sign language of the Pacific Northwest Plateau Sign LanguageLangue des Signes du Plateau(in the Canadian province of Québec)Native toCanada, United StatesRegionColumbia PlateauEthnicityVarious First Nations and Native Americans of the Columbia Plateau regionExtinct18th centuryLanguage familycontact pidginWriting systemnoneLanguage codesISO 639-3None (mis)GlottologNone Attested historical range of Plateau Sign Language among other sign languages in the US an...
Election in Hampshire, England 2002 Winchester City Council election ← 2000 2 May 2002 2003 → All 57 seats to Winchester City Council29 seats needed for a majority First party Second party Party Liberal Democrats Conservative Seats won 35 14 Popular vote 36,057 29.600 Percentage 44.6 36.6 Third party Fourth party Party Independent Labour Seats won 5 3 Popular vote 7,684 7,459 Percentage 9.5 9.2 Results by Ward Council contr...
Component of the US Military of the State of Indiana Indiana National GuardCountry United StatesTypeArmed ForcesPart ofUnited States Armed Forces United States Department of Defense National Guard BureauJoint Force Headquarters (JFHQ)Stout Army Air Field Indianapolis, Indiana, U.S.Motto(s)Always Ready, Always ThereWebsitewww.in.gov/indiana-national-guard/CommandersGovernor of IndianaGovernor Eric HolcombThe Adjutant General of IndianaMG R. Dale LylesState Command Sergeant MajorCSM D...
Untuk pembalap motor Jepang, lihat Takahisa Fujinami. Untuk pegulat profesional Jepang, lihat Tatsumi Fujinami. Fujinami dengan potret Kapten Tatsuji Matsuzaki Sejarah Kekaisaran Jepang Nama FujinamiPasang lunas 25 Agustus 1942Diluncurkan 20 April 1943Selesai 31 Juli 1943Dicoret 10 Desember 1944Nasib Tenggelam pada 27 Oktober 1944 Ciri-ciri umum Kelas dan jenis Kapal perusak kelas-YūgumoBerat benaman 2.520 ton panjang (2.560 t)Panjang 119,15 m (390 ft 11 in)Lebar 10,8...
George H. Crosby Manitou State ParkRugged backpacking trails traverse the inland North Shore HighlandsLocation of George H. Crosby Manitou State Park in MinnesotaShow map of MinnesotaGeorge H. Crosby Manitou State Park (the United States)Show map of the United StatesLocationLake, Minnesota, United StatesCoordinates47°28′44″N 91°6′43″W / 47.47889°N 91.11194°W / 47.47889; -91.11194Area6,682 acres (27.04 km2)Elevation1,391 ft (424 m)[1]...
Former German piano manufacturer Bogs & VoigtIndustryPianosFoundedPaul Richard Bogs and Adolf Ernst VoigtHeadquartersBerlin, Germany Bogs & Voigt was a piano manufacturer in Berlin, Germany. It was founded 1905 and existed up to 1939. The factory was located in 70 Warschauerstraße and 16a Boxhagenerstraße in Berlin. The owners Paul Richard Bogs (1871–1949) and Adolf Ernst Voigt were awarded an imperial and royal warrant of appointment to the courts of Austria-Hungary and Spain. ...
Finale de la Ligue Europa2017-2018 Le Groupama Stadium, hôte de la finale. Contexte Compétition Ligue Europa 2017-2018 Date 16 mai 2018 Stade Groupama Stadium Lieu Décines-Charpieu, France Affluence 55 768 spectateurs Résultat Olympique de Marseille 0 - 3 Atlético de Madrid Mi-temps 0 - 1 0 Acteurs majeurs Buteur(s) Atlético de Madrid 21e 49e Griezmann 89e Gabi Homme du match Antoine Griezmann Arbitrage Björn Kuipers Navigation Finale 2016-2017 Finale 2018-2019 mod...
Derby de Lisboa del 1910. Coreografia dei tifosi del Benfica prima del fischio di inizio di un derby di campionato. Il derby de Lisboa è la partita di calcio giocata tra Benfica e Sporting Lisbona. È altresì noto come Derby Eterno, Derby da Segunda Circular oppure Derby da Capital, mentre O Clássico fa riferimento alla partita tra Benfica e Porto. La rivalità tra le due compagini di Lisbona risale al 1907, quando otto giocatori del Benfica si trasferirono allo Sporting, il giorno prima d...
Municipality in North Rhine-Westphalia, GermanyHünxe Municipality FlagCoat of armsLocation of Hünxe within Wesel district Hünxe Show map of GermanyHünxe Show map of North Rhine-WestphaliaCoordinates: 51°38′30″N 6°46′2″E / 51.64167°N 6.76722°E / 51.64167; 6.76722CountryGermanyStateNorth Rhine-WestphaliaAdmin. regionDüsseldorf DistrictWesel Subdivisions6Government • Mayor (2020–25) Dirk Buschmann[1]Area • Total106.8&...
Difference in DNA among individuals or populations Part of a series onEvolutionary biologyDarwin's finches by John Gould Index Introduction Main Outline Glossary Evidence History Processes and outcomes Population genetics Variation Diversity Mutation Natural selection Adaptation Polymorphism Genetic drift Gene flow Speciation Adaptive radiation Co-operation Coevolution Coextinction Contingency Divergence Convergence Parallel evolution Extinction Natural history Origin of life Common descent H...
Government ministry in Kuwait Ministry of Foreign AffairsMinisterial Department overviewFormed1961; 63 years ago (1961)Preceding Ministerial DepartmentForeign Affairs Department BureauJurisdictionGovernment of KuwaitHeadquartersKuwait CityMinister responsibleAbdullah Al YahyaChild Ministerial DepartmentState of Kuwait Ambassadors Bureau Military Correspondents Attachés Bureau WebsiteOfficial Website of the Ministry of Foreign Affairs The Ministry of Foreign Affairs (Arabic:...