REvil Twins: Ransomware-as-a-Service program
ID: be2130e8-f1eb-5c54-9eb1-cd53ed397603
STIX ID: report--be2130e8-f1eb-5c54-9eb1-cd53ed397603
Feed Name: Group-IB Blog
This report provides an overview of the REvil (Sodinokibi) ransomware-as-a-service operation, describing affiliate recruitment and behavior, high-value incidents (e.g., Acer, JBS), rising ransom demands, common initial access vectors (phishing, malicious Office macros, RDP, purchased access, ProxyLogon/web shells), use of loaders like IcedID and Qakbot, post-exploitation tools (Cobalt Strike, Mimikatz, ProcDump), data exfiltration methods (WinSCP, cloud sync), and practical detection/hunting tips mapped to MITRE ATT&CK.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
