Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
  • Newsletter
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
  • Newsletter
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews
Cybercrime

REvil / Sodinokibi: The Big-Game Hunters Who Hit Kaseya, JBS, and Then Disappeared Twice

Jesse William McGrawBy Jesse William McGrawApril 26, 2026No Comments5 Mins Read47 Views
Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Crimson digital emblem dissolving into fragments evoking the REvil ransomware operation
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

REvil, also known as Sodinokibi or Sodin, was for two years the most aggressive, most public, and most lucrative ransomware operation in the world. It pioneered double extortion alongside Maze, popularised supply-chain attacks, ran auctions for stolen data, and threatened to leak Donald Trump’s personal documents. It is also the operation whose abrupt arrests by Russia’s FSB in early 2022 briefly suggested a fundamental shift in the geopolitics of ransomware.

Origins and lineage

REvil emerged in April 2019, picking up where the GandCrab operation had left off. GandCrab had run a successful RaaS from January 2018 to mid-2019, claiming to have extracted over $2 billion before announcing a public "retirement." Reverse engineering of REvil’s locker found multiple code overlaps with GandCrab. Most researchers concluded that GandCrab had not retired so much as rebranded, with key personnel and infrastructure rolling into the new operation.

The early REvil malware was a polished, modular Windows locker with a clean affiliate panel and a comparatively professional public profile. The operation rapidly recruited high-skill affiliates and within a year was rivalling Maze and Ryuk for the top of the leaderboard.

The "Happy Blog" and the auction model

REvil’s leak site, "Happy Blog," was distinctive both for its presentation and for innovations like a built-in auction model, letting attackers monetise stolen data even when victims refused to pay, by selling the data to other criminals or competitors. It was largely a publicity stunt that produced few recorded sales, but it generated extensive media coverage and signalled an operator that wanted to be talked about.

The public face of REvil was a forum operator using the handle Unknown (and later UNKN), who gave several interviews to Russian-language outlets. He bragged about revenue, openly mocked law enforcement, and was unusually candid about targeting choices.

Notable attacks

REvil’s victim list reads like a tour of strategically chosen high-leverage targets:

// Free tool

How does your own site score?

Run the same forty passive checks against your own domain — TLS and certificates, security headers, SPF and DMARC, cookies before consent, and what your stack quietly reveals. A grade out of 100 in about fifteen seconds.

No signup. Nothing installed. We only request what your site already serves publicly.

  • Travelex (December 2019), which paid an estimated $2.3 million.
  • Brown-Forman (Jack Daniel’s parent), with terabytes of internal documents stolen.
  • Grubman Shire Meiselas & Sacks (May 2020), the entertainment law firm, with stolen data from Madonna, Lady Gaga, Bruce Springsteen, and many others. The operators publicly threatened to release Trump-related documents and demanded $42 million.
  • Acer (March 2021), a $50 million ransom demand, a record at the time.
  • Quanta Computer (April 2021), with stolen Apple product schematics that the operators tried to use to extort Apple directly.
  • JBS Foods (May 2021), the world’s largest meat processor, which paid $11 million.
  • Kaseya VSA (July 2021), a supply-chain compromise that exploited a zero-day in the Kaseya remote management platform to push ransomware to roughly 1,500 downstream victims of managed service providers in a single weekend.

Kaseya was the operation’s high-water mark and, in retrospect, its peak. The scale and brazenness of the supply-chain attack triggered an extraordinary US response, including a direct warning from President Biden to Vladimir Putin.

The first disappearance

On 13 July 2021, days after the Kaseya attack, REvil’s entire infrastructure, leak site, payment portals, support chat, went dark. The disappearance was unannounced. Some affiliates were left with active negotiations and no platform to complete payment on. Several explanations circulated: a US government takedown, a voluntary retreat under heat, or pressure from Russia.

In September 2021 the operation reappeared. Researchers at Bitdefender released a universal decryptor for victims hit before the disappearance, made possible by intelligence partnerships with law enforcement. By October the FBI confirmed it had been inside REvil’s infrastructure and had supported a multinational operation that took some of it offline. By the end of October, REvil had gone dark again, this time more permanently.

The FSB arrests

In January 2022, in an unusual public statement, Russia’s Federal Security Service (FSB) announced it had arrested 14 members of REvil at the request of US authorities, seizing rubles, dollars, euros, and luxury cars. It was the first time Russia had publicly cooperated against a ransomware operation. The timing, weeks before Russia’s full-scale invasion of Ukraine, suggested it was a goodwill gesture made for diplomatic reasons, and the cooperation evaporated almost immediately afterward. Several of the arrested individuals were later released or never tried in any meaningful way; one, Yaroslav Vasinskyi, was extradited to the US and pleaded guilty in 2024.

The legacy

A REvil-branded leak site briefly reappeared in mid-2022, almost certainly a low-grade rebrand by remnant affiliates. It produced little credible victim activity. The original operation was effectively done.

But REvil’s influence is everywhere. The double-extortion model, the auction mechanism, the supply-chain compromise as a force-multiplier, all became standard features of subsequent operations. Many of the affiliates rolled into BlackCat/ALPHV, where REvil veterans helped seed another wave of high-profile attacks. The Russian-state stance on ransomware operators, selectively useful, deniable, ultimately tolerated, is the same posture that keeps current operations safe today.

REvil is the case study for how a single ransomware brand can shape the ecosystem far beyond its operational lifetime. The brand is gone. The playbook it wrote is still in active use.

The Ransomnews Monthly

One email a month. Original leak-site data, victim census updates, and the findings that did not make the articles. No spam, unsubscribe any time.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Previous ArticleConti: Anatomy of a Ransomware Corporation — and How It Imploded
Next Article BlackCat / ALPHV: The Rust-Powered RaaS That Ended in an Exit Scam
Jesse William McGraw

Jesse William McGraw, also known as GhostExodus, is a former insider threat and threat actor. He became the first person in recent U.S. history to be convicted of corrupting industrial control systems. Today he focuses on threat intelligence, OSINT, and public speaking, using his knowledge to bring awareness to the security risks that organisations and individuals face.

Related Posts

The Town 2025 ticketing data sold as a Ticketmaster breach

September 3, 2026

Micro-Comm hack is separate from the US water attacks

September 1, 2026

Love Electric driver data for sale: NI, licence numbers

August 28, 2026

Comments are closed.

// The Ransomnews Monthly

What leaked, what held up

One email a month: the datasets we verified, and the ones that fell apart under scrutiny.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

// Free tool

How does your own site score?

Forty passive checks on TLS, security headers, email spoofing and privacy. A grade out of 100 in about fifteen seconds.

No signup. Nothing installed. We only request what your site already serves publicly.

// Free tool

Were you in a leak?

Check whether an email address has surfaced in infostealer logs. No signup, no data stored.

Run StealerCheck

// Live data

Ransomtracker

Victims as they are posted to ransomware leak sites, tracked continuously and checked against the claims.

Open the tracker

9,520 confirmed attacks tracked

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links — when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

// Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker
  • Site Check

// Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

// Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.