Uncensored Interview With REvil Ransomware Operators
ID: 0086bae9-2ecd-58c5-968f-86665d251b6d
STIX ID: report--0086bae9-2ecd-58c5-968f-86665d251b6d
Feed Name: Cyble Blog
Threat Score
**Executive summary:** This document is an unedited interview with REvil (Sodinokibi) operators in which they describe their Ransomware-as-a-Service model, encryption/crypto design, data-exfiltration and double-extortion tactics, common intrusion vectors (RDP, brute-force, exploited Pulsar/Citrix vulnerabilities), preferred monetization (Monero, affiliate splits), and high-profile victims (Travelex, Grubman, Texas counties), claiming large annual revenue and operational scale.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
