logo

Attack trend alert: REvil ransomware

ID: 3a211baa-fa7c-543b-b2df-fe934143029a

STIX ID: report--3a211baa-fa7c-543b-b2df-fe934143029a

Feed Name: Expel Blog

Threat Score
75/100

Date Published: 2021-02-17

Date Updated: 2026-04-27

Author: Jon Hencinski; Michael Barclay

...
...

This Expel report describes an active REvil (SODINOKIBI) RaaS campaign observed targeting law firms in Germany and the United States, where attackers boosted malicious pages in Google search results to trick users into downloading ZIPs with JScript that stages a Cobalt Strike BEACON and leads to privilege escalation, lateral movement, and ransomware deployment. The post includes actionable detection rules (e.g., wscript/cscript executing scripts from user profiles, PowerShell base64 with external connections), containment and remediation steps (isolate hosts, re-image, timeline via C2/network traffic), and hardening advice (associate WSH files with Notepad, enable PowerShell Constrained Language, avoid exposing RDP, and maintain offline backups).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.