REvil (Sodinokibi) is a ransomware-as-a-service (RaaS) group known for double-extortion and data leaks on 'Happy Blog'.
Analyst brief
REvil (Sodinokibi) is a financially motivated cybercriminal group operating under a ransomware-as-a-service (RaaS) model. They target victims by encrypting their data and threatening to publish exfiltrated sensitive information on their 'Happy Blog' darknet site if the ransom is not paid. Their ransomware code shares similarities with the DarkSide group, and they employ double-extortion TTPs focused on data theft and lateral movement. Defenders should pay attention to preventing data exfiltration, monitoring for lateral movement, and maintaining isolated, up-to-date backups.
revil
crime
Sodinokibi ransomware group also known as REvil (Ransomware Evil) operates as a ransomware-as-a-service (RaaS) model. After the group compromised his victims, they would threaten to publish the victim's sensitive data on their darknet blog named 'Happy Blog', unless the ransom is paid. The ransomware malware code used by REvil is pretty similar to the ransomware code used by DarkSide - a different threat actor. REvil group claims to steal information after a successful attack on the supplier of the tech giant Apple and stole confidential schematics of their upcoming products.