# REvil

> As of 2026-07-23, REvil is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 2 threats spanning ransomware, threat actor. Also known as Sodinokibi. ATT&CK coverage spans 50 techniques across 13 tactics in 2 of 2 tracked threats. Most-observed techniques: T1036.005 (Match Legitimate Resource Name or Location), T1059.001 (PowerShell), T1070.004 (File Deletion).

- **Nation:** Russia
- **Tracked threats:** 2
- **Categories:** RANSOMWARE, THREAT_ACTOR
- **Also known as:** Sodinokibi
- **As of:** 2026-07-23

## ATT&CK techniques observed

50 techniques observed across 2 of 2 tracked threats. Tactics: Stealth (formerly Defense Evasion) (9), Discovery (8), Execution (6), Initial Access (6), Defense Impairment (5), Impact (5).

- [T1036.005](https://intel.threadlinqs.com/technique/T1036.005) Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion) — observed in 2 of 2 tracked threats
- [T1059.001](https://intel.threadlinqs.com/technique/T1059.001) PowerShell — Execution — observed in 2 of 2 tracked threats
- [T1070.004](https://intel.threadlinqs.com/technique/T1070.004) File Deletion — Stealth (formerly Defense Evasion) — observed in 2 of 2 tracked threats
- [T1071.001](https://intel.threadlinqs.com/technique/T1071.001) Web Protocols — Command and Control — observed in 2 of 2 tracked threats
- [T1082](https://intel.threadlinqs.com/technique/T1082) System Information Discovery — Discovery — observed in 2 of 2 tracked threats
- [T1106](https://intel.threadlinqs.com/technique/T1106) Native API — Execution — observed in 2 of 2 tracked threats
- [T1112](https://intel.threadlinqs.com/technique/T1112) Modify Registry — Defense Impairment — observed in 2 of 2 tracked threats
- [T1140](https://intel.threadlinqs.com/technique/T1140) Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion) — observed in 2 of 2 tracked threats
- [T1195](https://intel.threadlinqs.com/technique/T1195) Supply Chain Compromise — Initial Access — observed in 2 of 2 tracked threats
- [T1486](https://intel.threadlinqs.com/technique/T1486) Data Encrypted for Impact — Impact — observed in 2 of 2 tracked threats
- [T1489](https://intel.threadlinqs.com/technique/T1489) Service Stop — Impact — observed in 2 of 2 tracked threats
- [T1490](https://intel.threadlinqs.com/technique/T1490) Inhibit System Recovery — Impact — observed in 2 of 2 tracked threats
- [T1685](https://intel.threadlinqs.com/technique/T1685) Disable or Modify Tools — Defense Impairment — observed in 2 of 2 tracked threats
- [T1007](https://intel.threadlinqs.com/technique/T1007) System Service Discovery — Discovery — observed in 1 of 2 tracked threats
- [T1012](https://intel.threadlinqs.com/technique/T1012) Query Registry — Discovery — observed in 1 of 2 tracked threats

## Tracked threats

- [Kaseya VSA Supply-Chain Ransomware Incident — REvil/Sodinokibi Exploits CVE-2021-30116/30117/30118/30119/30120/30121 to Compromise 60 MSPs and 1,500+ Downstream Organizations](https://intel.threadlinqs.com/threat/TL-2026-1649) — CRITICAL
- [Armenia Detains Russian National Aleksandr Ermakov on US Extradition Request Tied to Sodinokibi/REvil Ransomware](https://intel.threadlinqs.com/threat/TL-2026-1446) — MEDIUM

## Related CVEs

7 CVEs referenced by tracked REvil activity.

- [CVE-2021-30201](https://intel.threadlinqs.com/cve/CVE-2021-30201)
- [CVE-2021-30121](https://intel.threadlinqs.com/cve/CVE-2021-30121)
- [CVE-2021-30120](https://intel.threadlinqs.com/cve/CVE-2021-30120)
- [CVE-2021-30119](https://intel.threadlinqs.com/cve/CVE-2021-30119)
- [CVE-2021-30118](https://intel.threadlinqs.com/cve/CVE-2021-30118)
- [CVE-2021-30117](https://intel.threadlinqs.com/cve/CVE-2021-30117)
- [CVE-2021-30116](https://intel.threadlinqs.com/cve/CVE-2021-30116)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/REvil
