Ransomware Group:  
Revil



Sponsored by Hudson RockUse Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business


Sites | External Information | Tools | Negotiations | Ransom Note(s) | Activity | Worldmap | Victims (98)

Sodinokibi ransomware group also known as REvil (Ransomware Evil) operates as a ransomware-as-a-service (RaaS) model. After the group compromised his victims, they would threaten to publish the victim's sensitive data on their darknet blog named 'Happy Blog', unless the ransom is paid. The ransomware malware code used by REvil is pretty similar to the ransomware code used by DarkSide - a different threat actor. REvil group claims to steal information after a successful attack on the supplier of the tech giant Apple and stole confidential schematics of their upcoming products.


Sites

Title Available Last Visit FQDN Screenshot
404 Not Found 🔴 2022-08-19 12:16:46.599604 dnpscnbaix6nkwvystl3yxglz7nteicqrou3t75tpcc5532cztc46qyd.onion N/A
404 Not Found 🔴 2022-08-19 12:17:40.270801 aplebzu47wgazapdqks6vrcv6zcnjppkbxbr6wketf56nf6aq2nmyoyd.onion N/A
Blog 🔴 2023-01-06 15:05:40.341977 blogxxu75w63ujqarv476otld7cyjkq4yoswzt4ijadkjwvg3vrvd5yd.onion N/A

External information

Tools used

Discovery RMM Tools Defense Evasion Credential Theft OffSec Networking LOLBAS Exfiltration
AdFind Cobalt Strike BITSAdmin PrivatLab
Bloodhound RClone
Sendspace

This information is provided by Ransomware-Tool-Matrix

 Negotiation chats

Name # Msg Initial Ransom Negotiated Ransom Paid
20210630 42 N/A N/A
20210709 1 N/A N/A
20210628 39 N/A N/A
20210708 28 N/A N/A
20210413 156 N/A N/A
20210407 15 N/A N/A
20210616 31 $500,000 $280,000
20210320 13 N/A N/A
20210617 67 N/A N/A
20201014 72 $7,500,000 $1,270,000
20210331 23 N/A N/A
20210604 10 N/A N/A
20210622 52 $100,000 $35,000
20210603 63 $2,500,000 $400,000
20210609 58 $300,000 $50,000
20201126 79 N/A N/A
20210613 132 $1,000,000 $300,000
20201104 63 N/A N/A
20210329 43 N/A N/A
20210401 78 $170,000 $100,000

This information is provided by Valéry Marchive & Julien Mousqueton

Ransom Note(s)

Activity over time

Worldmap

98 Victims

US flag

kusd.edu 

Company logo
Ransomware Group:

Discovery Date: 2022-11-28 20:34

Sector:

Group: 
 flag

Sunknowledge Services Inc 

Company logo
Ransomware Group:

Discovery Date: 2022-11-28 14:52

Sector:

Group: 
AU flag

medibank.com.au 

Company logo
Ransomware Group:

Discovery Date: 2022-11-07 13:27

Sector:

Group: 
 flag

Midea Group 

Company logo
Ransomware Group:

Discovery Date: 2022-09-01 10:45

Sector:

Group: 
 flag

Doosan Group 

Company logo
Ransomware Group:

Discovery Date: 2022-08-02 18:39

Sector:

Group: 
 flag

OptiProERP is a leading global provider of industry-specific ERP solutions for manufacture 

Company logo
Ransomware Group:

Discovery Date: 2022-07-25 18:54

Sector:

Group: 
 flag

Ludwig Freytag Group 

Company logo
Ransomware Group:

Discovery Date: 2022-05-12 13:41

Sector:

Group: 
 flag

Unicity International 

Company logo
Ransomware Group:

Discovery Date: 2022-05-03 15:29

Sector:

Group: 
 flag

Stratford University 

Company logo
Ransomware Group:

Discovery Date: 2022-04-22 21:26

Sector:

Group: 
 flag

Asfaltproductienijmegen 

Company logo
Ransomware Group:

Discovery Date: 2022-04-21 03:04

Sector:

Group: 
 flag

CYMZ 

Company logo
Ransomware Group:

Discovery Date: 2022-04-21 02:00

Sector:

Group: 
 flag

www.oil-india.com 

Company logo
Ransomware Group:

Discovery Date: 2022-04-21 00:40

Sector:

Group: 
 flag

Visotec Group www.visotec.com 

Company logo
Ransomware Group:

Discovery Date: 2022-04-20 22:33

Sector:

Group: 
 flag

PTT Exploration and Production - 720GB 

Company logo
Ransomware Group:

Discovery Date: 2021-10-15 00:31

Sector:

Group: 
 flag

ECKERD PERU S.A, INKAFARMA, MIFARMA 

Company logo
Ransomware Group:

Discovery Date: 2021-10-08 07:43

Sector:

Group: 
 flag

Join us on RAMP 

Company logo
Ransomware Group:

Discovery Date: 2021-10-07 09:47

Sector:

Group: 
 flag

Ronmor Holdings 

Company logo
Ransomware Group:

Discovery Date: 2021-10-01 09:12

Sector:

Group: 
 flag

Fimmick CRM Hong Kong (www.fimmick.com) 

Company logo
Ransomware Group:

Discovery Date: 2021-09-30 10:15

Sector:

Group: 
 flag

Fimmick CRM Honk Kong (www.fimmick.com) 

Company logo
Ransomware Group:

Discovery Date: 2021-09-30 07:48

Sector:

Group: 
 flag

Spiezle Architectural Group Inc. 

Company logo
Ransomware Group:

Discovery Date: 2021-09-16 08:14

Sector:

Group: 
 flag

ohiograting.com 

Company logo
Ransomware Group:

Discovery Date: 2021-09-11 09:10

Sector:

Group: 
 flag

Apex America 

Company logo
Ransomware Group:

Discovery Date: 2021-09-09 23:46

Sector:

Group: 
 flag

Allen, Dyer, Doppelt, & Gilchrist, P.A. 

Company logo
Ransomware Group:

Discovery Date: 2021-09-09 23:46

Sector:

Group: 
 flag

Betenbough Homes 

Company logo
Ransomware Group:

Discovery Date: 2021-09-09 23:46

Sector:

Group: 
 flag

CEC Vibration Products 

Company logo
Ransomware Group:

Discovery Date: 2021-09-09 23:46

Sector:

Group: 
 flag

ENPOL LLC 

Company logo
Ransomware Group:

Discovery Date: 2021-09-09 23:46

Sector:

Group: 
 flag

Iaffaldano, Shaw & Young LLP 

Company logo
Ransomware Group:

Discovery Date: 2021-09-09 23:46

Sector:

Group: 
 flag

angstrom automotive group 

Company logo
Ransomware Group:

Discovery Date: 2021-09-09 23:46

Sector:

Group: 
 flag

Agile Property Holdings 

Company logo
Ransomware Group:

Discovery Date: 2021-09-09 23:46

Sector:

Group: 
 flag

Möbelstadt Sommerlad 

Company logo
Ransomware Group:

Discovery Date: 2021-09-09 23:46

Sector:

Group: 
 flag

Gosiger 

Company logo
Ransomware Group:

Discovery Date: 2021-09-09 23:46

Sector:

Group: 
 flag

neroindustry.com 

Company logo
Ransomware Group:

Discovery Date: 2021-09-09 23:46

Sector:

Group: 
 flag

kuk.de / KREBS + KIEFER / 500GB 

Company logo
Ransomware Group:

Discovery Date: 2021-09-09 23:46

Sector:

Group: 
 flag

KASEYA ATTACK INFO 

Company logo
Ransomware Group:

Discovery Date: 2021-09-09 23:46

Sector:

Group: 
 flag

Daylesford - BHoldings - Bamford - The Wild Rabbit 

Company logo
Ransomware Group:

Discovery Date: 2021-09-09 23:46

Sector:

Group: 
 flag

Hx5, LLC 

Company logo
Ransomware Group:

Discovery Date: 2021-09-09 23:46

Sector:

Group: 
 flag

inocean.no / 2000 GB 

Company logo
Ransomware Group:

Discovery Date: 2021-09-09 23:46

Sector:

Group: 
 flag

Primo Water 

Company logo
Ransomware Group:

Discovery Date: 2021-09-09 23:46

Sector:

Group: 
 flag

lstaff.com / atworksprofessional / atworks.com 

Company logo
Ransomware Group:

Discovery Date: 2021-09-09 23:46

Sector:

Group: 
 flag

South Carolina Legal Services breach 

Company logo
Ransomware Group:

Discovery Date: 2021-09-09 23:46

Sector:

Group: 
 flag

ensingerplastics.com 

Company logo
Ransomware Group:

Discovery Date: 2021-09-09 23:46

Sector:

Group: 
 flag

Kaseya clients 

Company logo
Ransomware Group:

Discovery Date: 2021-07-02 00:00

Group: 
US flag

University Medical Center 

Company logo
Ransomware Group:

Discovery Date: 2021-06-28 00:00

Group: 
JP flag

Fujifilm 

Company logo
Ransomware Group:

Discovery Date: 2021-06-01 00:00

Group: 
 flag

JBS (meat processor) 

Company logo
Ransomware Group:

Discovery Date: 2021-05-30 00:00

Group: 
US flag

Sol Oriens 

Company logo
Ransomware Group:

Discovery Date: 2021-05-01 00:00

Group: 
BR flag

Brazil's Tribunal de Justiça do Estado do Rio Grande do Sul 

Company logo
Ransomware Group:

Discovery Date: 2021-04-28 00:00

Group: 
 flag

Apple MacBook via supplier Quanta Computer 

Company logo
Ransomware Group:

Discovery Date: 2021-04-20 00:00

Group: 
FR flag

Asteelflash 

Company logo
Ransomware Group:

Discovery Date: 2021-04-01 00:00

Group: 
FR flag

Pierre Fabre 

Company logo
Ransomware Group:

Discovery Date: 2021-03-31 00:00

Sector: Chemical

Group: 
FR flag

Pierre Fabre 

Company logo
Ransomware Group:

Discovery Date: 2021-03-31 00:00

Sector: Chemical

Group: 
 flag

Acer 

Company logo
Ransomware Group:

Discovery Date: 2021-03-13 00:00

Group: 
 flag

Acer 

Company logo
Ransomware Group:

Discovery Date: 2021-03-01 00:00

Group: 
 flag

Gyrodata Incorporated 

Company logo
Ransomware Group:

Discovery Date: 2021-02-21 00:00

Sector: Energy

Group: 
US flag

Standley Systems (vendor to Healthcare Sector) 

Company logo
Ransomware Group:

Discovery Date: 2021-02-01 00:00

Group: 
 flag

Dairy Farm Group 

Company logo
Ransomware Group:

Discovery Date: 2021-01-14 00:00

Group: 
GB flag

Transform Hospital Group LTD 

Company logo
Ransomware Group:

Discovery Date: 2020-12-01 00:00

Group: 
US flag

Managed[.]com (Web Hosting Provider for Columbus County, NC, Griffin Hospital in CT, Arizona Judicial Branch, and Jackson County, OR, among others) 

Company logo
Ransomware Group:

Discovery Date: 2020-11-16 00:00

Group: 
US flag

Beacon Health Solutions 

Company logo
Ransomware Group:

Discovery Date: 2020-10-01 00:00

Group: 
CL flag

Banco Estado (Public Bank) 

Company logo
Ransomware Group:

Discovery Date: 2020-09-07 00:00

Group: 
 flag

Haberdashers’ Monmouth Schools 

Company logo
Ransomware Group:

Discovery Date: 2020-09-01 00:00

Group: 
US flag

Ma Labs 

Company logo
Ransomware Group:

Discovery Date: 2020-08-24 00:00

Group: 
US flag

Brown-Forman Corp (alcohol manufacturer) 

Company logo
Ransomware Group:

Discovery Date: 2020-08-01 00:00

Group: 
 flag

Valley Health Systems 

Company logo
Ransomware Group:

Discovery Date: 2020-08-01 00:00

Group: 
US flag

National Western Life (insurance) 

Company logo
Ransomware Group:

Discovery Date: 2020-08-01 00:00

Group: 
AR flag

Telecom Argentina 

Company logo
Ransomware Group:

Discovery Date: 2020-07-18 00:00

Group: 
US flag

Cooke County Sheriff's Office 

Company logo
Ransomware Group:

Discovery Date: 2020-07-04 00:00

Group: 
US flag

Actuaries and Associates (retirement specialist) 

Company logo
Ransomware Group:

Discovery Date: 2020-07-01 00:00

Group: 
ES flag

ADIF (Spanish railway manager) 

Company logo
Ransomware Group:

Discovery Date: 2020-07-01 00:00

Group: 
US flag

AAA Ambulance Service 

Company logo
Ransomware Group:

Discovery Date: 2020-07-01 00:00

Group: 
AU flag

Lion (Beverage giant) 

Company logo
Ransomware Group:

Discovery Date: 2020-06-09 00:00

Group: 
US flag

Symbiotic LLC 

Company logo
Ransomware Group:

Discovery Date: 2020-06-01 00:00

Group: 
CA flag

Goodman Mintz LLP 

Company logo
Ransomware Group:

Discovery Date: 2020-06-01 00:00

Group: 
CH flag

ZEGG Hotels & Store 

Company logo
Ransomware Group:

Discovery Date: 2020-06-01 00:00

Group: 
US flag

Crozer-Keystone Health System (Delaware County, PA) 

Company logo
Ransomware Group:

Discovery Date: 2020-06-01 00:00

Group: 
ZA flag

Telkom 

Company logo
Ransomware Group:

Discovery Date: 2020-05-29 00:00

Group: 
LK flag

Sri Lanka Telecom 

Company logo
Ransomware Group:

Discovery Date: 2020-05-23 00:00

Group: 
AU flag

Insport (sports store) 

Company logo
Ransomware Group:

Discovery Date: 2020-05-16 00:00

Group: 
GB flag

Elexon 

Company logo
Ransomware Group:

Discovery Date: 2020-05-14 00:00

Sector: Energy

Group: 
US flag

Harvest Food Distributors (San Diego) 

Company logo
Ransomware Group:

Discovery Date: 2020-05-03 00:00

Group: 
US flag

Sherwood Food Distributors (Detroit) 

Company logo
Ransomware Group:

Discovery Date: 2020-05-03 00:00

Group: 
US flag

National Association of Eating Disorders 

Company logo
Ransomware Group:

Discovery Date: 2020-04-01 00:00

Group: 
 flag

SeaChange International (supplier of video delivery software) 

Company logo
Ransomware Group:

Discovery Date: 2020-04-01 00:00

Group: 
US flag

Town of Jupiter 

Company logo
Ransomware Group:

Discovery Date: 2020-03-21 00:00

Group: 
US flag

10x Genomics 

Company logo
Ransomware Group:

Discovery Date: 2020-03-13 00:00

Sector: Chemical

Group: 
US flag

Brooks International (business management consultant) 

Company logo
Ransomware Group:

Discovery Date: 2020-03-01 00:00

Group: 
AU flag

Geidi (IT serves) 

Company logo
Ransomware Group:

Discovery Date: 2020-03-01 00:00

Group: 
US flag

Mountain View Los Altos Union High School District 

Company logo
Ransomware Group:

Discovery Date: 2020-01-29 00:00

Group: 
DE flag

Gedia Automotive Group 

Company logo
Ransomware Group:

Discovery Date: 2020-01-27 00:00

Group: 
US flag

Tillamook County 

Company logo
Ransomware Group:

Discovery Date: 2020-01-22 00:00

Group: 
US flag

Artech Information Systems 

Company logo
Ransomware Group:

Discovery Date: 2020-01-05 00:00

Group: 
GB flag

Travelex 

Company logo
Ransomware Group:

Discovery Date: 2019-12-31 00:00

Group: 
US flag

LogicalNet (MSP) Schenectady, NY 

Company logo
Ransomware Group:

Discovery Date: 2019-12-25 00:00

Group: 
US flag

Synoptek 

Company logo
Ransomware Group:

Discovery Date: 2019-12-24 00:00

Group: 
US flag

CyrusOne 

Company logo
Ransomware Group:

Discovery Date: 2019-12-05 00:00

Group: 
US flag

Englewood Complete Technology Services 

Company logo
Ransomware Group:

Discovery Date: 2019-11-25 00:00

Group: 
US flag

Alphabroder 

Company logo
Ransomware Group:

Discovery Date: 2019-10-14 00:00

Group: 
US flag

Percsoft and the Digital Dental Record 

Company logo
Ransomware Group:

Discovery Date: 2019-08-26 00:00

Group: