Site navigation

REvil Ransomware Group: What Happened to the Notorious Cybercriminals?

Michael Behr

,

REvil ransomware
Once one of the world’s most daring and ambitious criminal enterprises, REvil has seen its fortunes decline in recent months.

Members of REvil, one of cyberspace’s most notorious ransomware groups, have been arrested by Russian authorities.

According to the FSB, REvil has now “ceased to exist,” with the group dismantled and 14 of its members charged.

In addition, it claims to have seized over 400 million rubles (around $4m), plus around $600,000 and 500,000 euros, along with cryptocurrencies and 20 cars bought it claims were purchased with illicit funds.

The FSB added that the group’s infrastructure has also been neutralised.

This is not the first time that members of REvil have been arrested. Two members of the group were arrested back in November last year. Operation GoldDust saw 19 different organisations, including those in the UK, managed to net seven people connected to REvil over 2021. The suspects were arrested in Poland, Ukraine, South Korea, and Kuwait.

However, what makes this recent development remarkable is that the suspects were arrested by Russian police. Russia has generally taken a tolerant view to cybercriminal groups based in the country, so long as they don’t target indigenous organisations.

Perhaps even stranger is that the FSB claims to have acted using information provided by US authorities. According to a statement from the FSB, the arrests were prompted by an appeal from US authorities, who provided intelligence on the suspects and their involvement in ransomware attacks.

The US has been keen to bring REvil to justice over the attacks that hit its infrastructure, offering rewards of $10m for information on its members.

It is unlikely though that any of the suspects will face extradition to the US.


Recommended


The Kaseya attack was a landmark incident in a remarkable year for ransomware. By hitting a major supplier of third-party software, REvil was able to hit potentially thousands of organisations. The hackers then demanded $70 million in bitcoins for a universal decryptor.

Despite being linked to some of the biggest cyber-attacks of 2021, the past few months have not been easy for REvil. The group’s portal on the dark web was taken down in the summer, preventing REvil from taking ransomware payments.

The timing has sparked speculation about the reason for the move – it came at the same time as a call between US President Joe Biden and Russian President Vladimir Putin. With cybersecurity on the agenda, analysts speculated that Russian authorities had taken action to curb a rogue element operating on the country’s soil.

However, an individual claiming to represent REvil later claimed that they shut down operations after believing a group member had been arrested.

While the portal returned two months later, there was one final twist in REvil’s fortunes. The group accidentally leaked a decryptor for the Kaseya ransomware.

Michael Behr

Senior Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data