logo

REvil Twins: Ransomware-as-a-Service program

ID: be2130e8-f1eb-5c54-9eb1-cd53ed397603

STIX ID: report--be2130e8-f1eb-5c54-9eb1-cd53ed397603

Feed Name: Group-IB Blog

Threat Score
85/100

Date Published: 2021-06-30

Date Updated: 2026-04-27

...
...

This report provides an overview of the REvil (Sodinokibi) ransomware-as-a-service operation, describing affiliate recruitment and behavior, high-value incidents (e.g., Acer, JBS), rising ransom demands, common initial access vectors (phishing, malicious Office macros, RDP, purchased access, ProxyLogon/web shells), use of loaders like IcedID and Qakbot, post-exploitation tools (Cobalt Strike, Mimikatz, ProcDump), data exfiltration methods (WinSCP, cloud sync), and practical detection/hunting tips mapped to MITRE ATT&CK.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.