Activity timeline
REvil appears in 2 tracked threats between and .
ATT&CK techniques observed
- T1036.005 Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion)observed in 2 of 2 tracked threats
- T1059.001 PowerShell — Executionobserved in 2 of 2 tracked threats
- T1070.004 File Deletion — Stealth (formerly Defense Evasion)observed in 2 of 2 tracked threats
- T1071.001 Web Protocols — Command and Controlobserved in 2 of 2 tracked threats
- T1082 System Information Discovery — Discoveryobserved in 2 of 2 tracked threats
- T1106 Native API — Executionobserved in 2 of 2 tracked threats
- T1112 Modify Registry — Defense Impairmentobserved in 2 of 2 tracked threats
- T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 2 of 2 tracked threats
- T1195 Supply Chain Compromise — Initial Accessobserved in 2 of 2 tracked threats
- T1486 Data Encrypted for Impact — Impactobserved in 2 of 2 tracked threats
- T1489 Service Stop — Impactobserved in 2 of 2 tracked threats
- T1490 Inhibit System Recovery — Impactobserved in 2 of 2 tracked threats
- T1685 Disable or Modify Tools — Defense Impairmentobserved in 2 of 2 tracked threats
- T1007 System Service Discovery — Discoveryobserved in 1 of 2 tracked threats
- T1012 Query Registry — Discoveryobserved in 1 of 2 tracked threats
Tracked threats
- Kaseya VSA Supply-Chain Ransomware Incident — REvil/Sodinokibi Exploits CVE-2021-30116/30117/30118/30119/30120/30121 to Compromise 60 MSPs and 1,500+ Downstream OrganizationsCRITICAL
- Armenia Detains Russian National Aleksandr Ermakov on US Extradition Request Tied to Sodinokibi/REvil RansomwareMEDIUM