logo

REvil Ransomware Uses DLL Sideloading

ID: bacd4cf7-e619-5601-8335-f24e0574aeff

STIX ID: report--bacd4cf7-e619-5601-8335-f24e0574aeff

Feed Name: McAfee Labs Blog

Threat Score
78/100

Date Published: 2021-07-16

Date Updated: 2026-04-28

Author: McAfee Labs

...
...

This McAfee analysis details the REvil/Sodinokibi ransomware campaign, including DLL side‑loading via a signed Microsoft binary, RC4/Salsa20-based payload and encryption, localization checks to avoid certain countries, termination of wide-ranging applications and services, evidence of exploitation through CVE-2019-2725 and Kaseya VSA, and provided IOCs and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.