logo

REvil Actor Accuses Russia of Planning 2021 Kaseya Attack

ID: d392382b-381e-5526-8987-5b43a51be7ef

STIX ID: report--d392382b-381e-5526-8987-5b43a51be7ef

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2025-08-11

Date Updated: 2026-04-21

Author: Alexander Culafi

...
...

This report summarizes a DEF CON discussion and follow-up reporting about the REvil ransomware-as-a-service operation, highlighting the July 2021 Kaseya supply-chain attack that compromised VSA and affected over 1,000 downstream organizations. It reviews REvil's affiliate model, operational tradecraft (leak site use, dedicated comms, stable decryptors, outsourcing money laundering), the group's takedown timeline, and statements from a convicted affiliate who alleges Russian government involvement in orchestrating and executing the attack.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.