Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews

REVIL · Threat actor profile

// THREAT ACTOR

REVIL_

Dormant

REvil — also known as Sodinokibi — was a high-profile ransomware-as-a-service operation linked to attacks on Kaseya, JBS Foods, and Travelex between 2019 and 2021. Russian authorities announced the arrest of several alleged members in early 2022, although successor branding briefly resurfaced afterwards.

For Ransomnews editorial coverage of REVIL — incident write-ups, attribution notes, and additional context — see the Threat Groups archive or run a site search.

41 Victims tracked
0 / 10 Active mirrors
2021-09-09 First listing
2022-11-29 Most recent

Victims by year

  • 2022 13
  • 2021 28

Leak site mirrors

10 mirrors tracked, 0 currently reachable. These are criminal-infrastructure URLs — links are deliberately not provided.

  • dnpscnbaix6nkwvystl3yxglz7nteicqrou3t75tpcc5532cztc46qyd.onion 404 Not Found snapshot · 2022-08-19 14:15
  • aplebzu47wgazapdqks6vrcv6zcnjppkbxbr6wketf56nf6aq2nmyoyd.onion 404 Not Found snapshot · 2022-08-19 10:13
  • blogxxu75w63ujqarv476otld7cyjkq4yoswzt4ijadkjwvg3vrvd5yd.onion Blog snapshot · 2023-01-06 18:05
  • 2wub3njb7zvmnn6xohbuizjcbvy4w5dvlb4puesry3rrl6gx4452ezid.onion snapshot · 2024-12-10 15:25
  • 54xj22qsftuzs6bhcistgz27reblgijdjggkgb3fdhfgl3ghkmzk7dad.onion snapshot · 2024-12-10 15:25
  • 65x5syrn4gmgfnicrhyfwkokw5x3xipxer2z4vhhckrh756v6m5272qd.onion snapshot · 2024-12-10 15:25
  • fsgwyl2xd2h5s43er7epr6vuqu5eddmmtgp6cq7khmkoe3ba4d37w7ad.onion snapshot · 2024-12-10 15:26
  • rrjwr4jsju3nuwjz77hbcquiuq5hc3oc7yxlgi5rxeazehf7mlkzcvid.onion snapshot · 2024-12-10 15:26
  • ttn4gqpgvyy6tuezexxhwiukmm2t6zzawj6p3w3jprve36f43zxr24qd.onion snapshot · 2024-12-10 15:26
  • landxxeaf2hoyl2jvcwuazypt6imcsbmhb7kx3x33yhparvtmkatpaad.onion snapshot · 2024-12-10 22:39

Recent victims

The 50 most recent victims claimed by REVIL. Total in the index: 41.

Date listed Victim Description
2022-11-29 kusd.edu
2022-11-28 Sunknowledge Services Inc
2022-11-07 medibank.com.au
2022-09-01 Midea Group
2022-08-18 Asfaltproductienijmegen
2022-08-18 CYMZ
2022-08-18 Visotec Group www.visotec.com
2022-08-18 Stratford University
2022-08-18 www.oil-india.com
2022-08-18 Unicity International
2022-08-18 Ludwig Freytag Group
2022-08-18 Doosan Group
2022-08-18 OptiProERP is a leading global provider of industry-specific ERP solutions for manufacture
2021-10-15 PTT Exploration and Production - 720GB
2021-10-08 ECKERD PERU S.A, INKAFARMA, MIFARMA
2021-10-07 Join us on RAMP
2021-10-01 Ronmor Holdings
2021-09-30 Fimmick CRM Hong Kong (www.fimmick.com)
2021-09-30 Fimmick CRM Honk Kong (www.fimmick.com)
2021-09-16 Spiezle Architectural Group Inc.
2021-09-11 ohiograting.com
2021-09-09 Apex America
2021-09-09 Allen, Dyer, Doppelt, & Gilchrist, P.A.
2021-09-09 Betenbough Homes
2021-09-09 CEC Vibration Products
2021-09-09 ENPOL LLC
2021-09-09 Iaffaldano, Shaw & Young LLP
2021-09-09 angstrom automotive group
2021-09-09 Agile Property Holdings
2021-09-09 Möbelstadt Sommerlad
2021-09-09 Gosiger
2021-09-09 neroindustry.com
2021-09-09 kuk.de / KREBS + KIEFER / 500GB
2021-09-09 KASEYA ATTACK INFO
2021-09-09 Daylesford - BHoldings - Bamford - The Wild Rabbit
2021-09-09 Hx5, LLC
2021-09-09 inocean.no / 2000 GB
2021-09-09 Primo Water
2021-09-09 lstaff.com / atworksprofessional / atworks.com
2021-09-09 South Carolina Legal Services breach
2021-09-09 ensingerplastics.com

← Back to Ransomtracker

Statistics on this page are computed by Ransomnews from a live leak-site monitoring feed. Numbers update every ten minutes. Operator-written victim descriptions are truncated and shown in snippet form only. Source data: RansomLook (CC BY 4.0), aggregated and adapted by Ransomnews.

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links — when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

// Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker

// Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

// Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.