logo

Uncensored Interview With REvil Ransomware Operators

ID: 0086bae9-2ecd-58c5-968f-86665d251b6d

STIX ID: report--0086bae9-2ecd-58c5-968f-86665d251b6d

Feed Name: Cyble Blog

Threat Score
80/100

Date Published: 2024-11-04

Date Updated: 2026-07-16

...
...

**Executive summary:** This document is an unedited interview with REvil (Sodinokibi) operators in which they describe their Ransomware-as-a-Service model, encryption/crypto design, data-exfiltration and double-extortion tactics, common intrusion vectors (RDP, brute-force, exploited Pulsar/Citrix vulnerabilities), preferred monetization (Monero, affiliate splits), and high-profile victims (Travelex, Grubman, Texas counties), claiming large annual revenue and operational scale.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.