logo

REvil: Analysis of Competing Hypotheses

ID: bbe42c2c-2b9e-5a84-92af-0cccd2938df3

STIX ID: report--bbe42c2c-2b9e-5a84-92af-0cccd2938df3

Feed Name: ReliaQuest Blog

Threat Score
75/100

Date Published: 2021-07-28

Date Updated: 2026-04-29

...
...

This ReliaQuest ACH report analyzes the sudden disappearance of the REvil (Sodinokibi) ransomware group in July 2021 by weighing six hypotheses — law enforcement action, technical difficulties, internal strife, rebrand, retirement, and mixed/wildcard scenarios — and concludes that law enforcement action and/or a rebrand are the most likely explanations while emphasizing persistent uncertainty and ongoing ransomware risk to organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.