• Cryptocurrency
  • Earnings
  • Enterprise
  • About TechBooky
  • Submit Article
  • Advertise Here
  • Contact Us
TechBooky
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
TechBooky
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Home Security

Dismantling A Prolific Cybercriminal Empire: REvil Arrests And Re-emergence

Paul Balo by Paul Balo
September 30, 2022
in Security
Share on FacebookShare on Twitter

We’ve recently seen reports that the REvil ransomware gang is back online after the January 2022 arrests of several its members by Russian authorities claiming to dismantle the group and the November 2021 arrests of two members by U.S. authorities. While it remains to be seen if this re-emergence of REvil includes its most aggressive members with the same technical skills or is merely a copycat group lifting off the old name and parts of the infrastructure, we have seen a steady stream of new REvil binaries in the wild. Currently our main hypothesis is that one or several individuals have gained control over the old REvil Happy Blog and some binary source code. It is important to note that REvil was already a re-branding of GandCrab to gain influence and attention, therefore it is remarkable that the name REvil, given its infamy, is being used again/still. This gives us reason to believe the original key members of REvil group are most likely not involved.

However, reemergence or not, it has our interest.   

The Trellix Advanced Research Center’s threat intelligence group has long-studied REvil, its predecessor GandCrab and other actors like them. In this blog we will often reference research we have done in the past on both GandCrab and REvil. For those interested in previous research we have performed check the following blogs:

Gandcrab:
Virus Bulletin 2019: Different ways to cook a crab: GandCrab Ransomware-as-a-Serive (RaaS) analysed in depth

REvil;

Episode 1: What the code tells us
Episode 2: The Allstars
Episode 3: Follow the Money
Episode 4: Cresendo

To defend against cybercriminals, we must understand how they think and how they work. To truly end operations of a cybercriminal enterprise, or a ransomware operation in this case, the individual person or group responsible for a cyberattack has to be discovered and prosecuted, but it can be notoriously difficult for law enforcement to determine who those affiliate members behind specific attacks are.

Leading up to the FBI’s seizure of funds stolen by REvil and the indictments and arrests of some of the group’s members, Trellix described a novel technique to enumerate key ransomware gang members. We described this extensively in our VB2019 publication on GandCrab and a past REvil blog. In this blog, we will take you all the way from the steps REvil took to build their cybercriminal enterprise through the missteps that eventually led to their downfall.

Building a Cybercriminal Enterprise

Our team’s research into Conti reiterated much of what we learned from our study of REvil. Cybercriminal groups are growing in their sophistication and operations, building everything from HR, to payroll, to culture and employee recognition programs, to call centers. They are fully functioning organizations, with marketing and user support. And as they scale and build trust in and dependencies on others, they often open doors for researchers and law enforcement to poke holes in their operations and techniques which can provide new ways to uncover who exactly their affiliate members are.

Figure 1: piece of internal marketing demonstrating brand and vision to attract talent by Revil’s predecessor GandCrab ransomware.

When we think of a cybercrime “empire,” here are the key ingredients we expect to observe in the wild:

1.   Stable Product: For a group to be successful, it must have an easy to use and stable malware, and in the case of ransomware, an even more stable decryptor.

2.    Technology & Marketing to Scale: Many ransomware groups and other cybercriminal gangs promote their activities, mission, and job postings on carefully curated dark web sites used to instill fear in victims/potential victims. The way an organization brands itself is also critical to attracting and retaining affiliate members. To scale a Ransomware-as-a-Service (RaaS) group we often observe groups deploying a centralized panel to communicate with victims and request binaries and decryptors, as opposed to negotiating via email with hundreds of victims at any given moment.

3.   The Right People: Hiring the most talented affiliates is important, but as with many enterprises, many groups will still require members to complete trial periods to prove they are a fit.

4.  Strategic Partnerships: To scale even more, cybercriminal groups leverage partnerships to execute areas of their business – everywhere from malware obfuscation services to call centers to Bitcoin laundering services. This allows the group to focus on their own specialty.

5.    Pay Your Debts: Loyalty is perhaps the most important factor in keeping cybercriminal groups operational. Malware authors have made it easy for management to know what they’re owed by creating a tracking mechanism to determine commissions across the team responsible for an attack. 

 

Signs of an organization on the edge of falling are often seen when they forget to stay humble and loyalty goes out the window or they make a sloppy mistake. The growth of the infrastructure and operations and human capital means growth of opportunities to mess up and increased likelihood for investigators like us to find novel ways to study them.

Figure 2: Announcement that a popular Malware Obfuscation Service is partnering with GandCrab Ransomware. Details that its users are receiving a nice discount to use this specific services.

 

REvil In Action

REvil first appeared in the wild in as Sodinokibi at the end of April 2019. Emerging from the GandCrab group, Sodinokibi aka REvil, the group quickly established operations, building a high-volume RaaS empire responsible for the theft of millions of dollars across countries and industries, and some of the most significant ransomware attacks in recent history. RaaS groups operate with a core group of people maintaining the code and another group, known as affiliates, spreading the ransomware. Additional support functions and partners are key to operations, and it is common for RaaS groups earn a commission on ransoms collected from victims. However, there were also groups like the Conti group that instead of paying a percentage had their affiliates on payroll.

 

 

The article was written by John Fokker and was sent to TechBooky by Caitlin Robertson. John Fokker is  Head of Threat Intelligence & Principal Engineer at Trellix

Related Posts:

  • mgm-3-rt-bb-230914_1694697039563_hpMain
    MGM Resorts' Wake-Up Call From Scattered Spider Hackers
  • 1_7l5OQaemuQJLuQxYXze38g
    The Latest In The Microsoft-Google Clash is Cloud Services
  • WhatsApp-754×424
    WhatsApp Introduces New Privacy Features: Users Can…
  • instagram-blend
    Instagram Blend: Custom Content Suggestions
  • tiktok-20190415
    Group Chat is Coming To TikTok's Platform
  • imagem_2022-09-20_011749365
    Sony Has Begun Testing Cloud Streaming PS5 Games
  • Telegram–1424×802
    Users Can Now Signup On Telegram Without A SIM Card,…
  • skynews-russia-hacker_5812455
    Russian Hackers Target WhatsApp for Data on Ukraine

Discover more from TechBooky

Subscribe to get the latest posts sent to your email.

Tags: ransomwarerevilsecurity
Paul Balo

Paul Balo

Paul Balo is the founder of TechBooky and a highly skilled wireless communications professional with a strong background in cloud computing, offering extensive experience in designing, implementing, and managing wireless communication systems.

BROWSE BY CATEGORIES

Select Category

    Receive top tech news directly in your inbox

    subscription from
    Loading

    Freshly Squeezed

    • Tech Hype vs. Reality – When Big Tech Missed the Mark Pt. 1 May 9, 2025
    • Top 10 Fee-Free Fintech Apps Nigerians Are Turning To After CBN’s New Charges May 8, 2025
    • Airtel Launches Mobile Money in 2026 to Rival M-Pesa & MoMo May 8, 2025
    • Nigeria Hits 172M Mobile Subscriptions; MTN Tops 90M Barrier May 8, 2025
    • WhatsApp Developing AI Chat Wallpapers & Message Summaries May 8, 2025
    • Bill Gates to Wind Down Foundation by 2045, Slams Elon Musk Over USAID Cuts May 8, 2025

    Browse Archives

    May 2025
    MTWTFSS
     1234
    567891011
    12131415161718
    19202122232425
    262728293031 
    « Apr    

    Popular Tags

    africa (135) AI (497) android (367) app (717) Apple (576) artificial intelligence (419) business (482) china (132) cryptocurrency (209) ecommerce (122) enterprise (287) facebook (507) fintech (244) funding (121) gadget (558) gaming (201) google (709) government (469) instagram (173) internet (466) ios (291) iphone (246) meta (116) microsoft (369) mobile (352) new feature (384) nigeria (440) privacy (158) research (140) samsung (185) security (421) smartphone (277) social media (835) software (509) startup (419) streaming (174) telecom (242) tips (372) twitter (289) united states (216) users (158) videos (127) website (173) whatsapp (201) youtube (138)

    Quick Links

    • About TechBooky
    • Advertise Here
    • Contact us
    • Submit Article
    • Privacy Policy

    About Us

    TechBooky

    TechBooky is a social Tech blog with a special focus on the budding African Technology sector. TechBooky is currently based in Abuja, Nigeria.

    Recent News

    Tech Hype vs. Reality – When Big Tech Missed the Mark Pt. 1

    Tech Hype vs. Reality – When Big Tech Missed the Mark Pt. 1

    May 9, 2025
    Top 10 Fee-Free Fintech Apps Nigerians Are Turning To After CBN’s New Charges

    Top 10 Fee-Free Fintech Apps Nigerians Are Turning To After CBN’s New Charges

    May 8, 2025
    Airtel Launches Mobile Money in 2026 to Rival M-Pesa & MoMo

    Airtel Launches Mobile Money in 2026 to Rival M-Pesa & MoMo

    May 8, 2025
    MTN Recovers ₦32 Billion in USSD Fees

    Nigeria Hits 172M Mobile Subscriptions; MTN Tops 90M Barrier

    May 8, 2025
    WhatsApp Developing AI Chat Wallpapers & Message Summaries

    WhatsApp Developing AI Chat Wallpapers & Message Summaries

    May 8, 2025
    Bill Gates to Wind Down Foundation by 2045, Slams Elon Musk Over USAID Cuts

    Bill Gates to Wind Down Foundation by 2045, Slams Elon Musk Over USAID Cuts

    May 8, 2025
    • Login

    © 2021 Design By Tech Booky Elite

    Generic selectors
    Exact matches only
    Search in title
    Search in content
    Post Type Selectors
    • African
    • Artificial Intelligence
    • Gadgets
    • Metaverse
    • Tips
    • About TechBooky
    • Advertise Here
    • Submit Article
    • Contact us

    © 2021 Design By Tech Booky Elite

    Discover more from TechBooky

    Subscribe now to keep reading and get access to the full archive.

    Continue reading

    We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.Ok