The LV ransomware group uses REvil malware to target companies over perceived data protection failures.
Analyst brief
The LV ransomware group is a cybercriminal operation utilizing REvil group malware, known for targeting companies they accuse of failing consumer data protection obligations. They have claimed responsibility for compromising the corporate network of Groupe Reorev. Their key TTPs include network intrusion and data exfiltration, likely leveraging double extortion tactics with REvil-linked tools. Defenders should focus on initial access vectors common to criminal ransomware operations (especially remote access vulnerabilities and phishing), monitor for REvil-related Indicators of Compromise, and strengthen data inventory and egress monitoring to prevent data leaks.
lv
crime
LV ransomware group main message: "Here are companies which didn't meet consumer data protection obligations. They rejected to fix their mistakes, they rejected to protect this data in the case when they could and had to ptotect it. These companies prefered to sell their private information, their employees' and customers' personal data". Security researchers claim that the LV group is utilizing the REvil ransomware group malware. The LV group claim to have compromised the corporate network of Groupe Reorev.
What rationale does the LV ransomware group use for targeting victims?+
The LV group targets companies they accuse of failing consumer data protection obligations, claiming these entities prefer to sell private information and refused to fix their mistakes or protect data when they could and had to.
Which existing ransomware family's malware does the LV ransomware group utilize?+
The LV ransomware group is utilizing the REvil ransomware group's malware.