Members of REvil, one of cyberspace’s most notorious ransomware groups, have been arrested by Russian authorities.
According to the FSB, REvil has now “ceased to exist,” with the group dismantled and 14 of its members charged.
In addition, it claims to have seized over 400 million rubles (around $4m), plus around $600,000 and 500,000 euros, along with cryptocurrencies and 20 cars bought it claims were purchased with illicit funds.
The FSB added that the group’s infrastructure has also been neutralised.
This is not the first time that members of REvil have been arrested. Two members of the group were arrested back in November last year. Operation GoldDust saw 19 different organisations, including those in the UK, managed to net seven people connected to REvil over 2021. The suspects were arrested in Poland, Ukraine, South Korea, and Kuwait.
However, what makes this recent development remarkable is that the suspects were arrested by Russian police. Russia has generally taken a tolerant view to cybercriminal groups based in the country, so long as they don’t target indigenous organisations.
Perhaps even stranger is that the FSB claims to have acted using information provided by US authorities. According to a statement from the FSB, the arrests were prompted by an appeal from US authorities, who provided intelligence on the suspects and their involvement in ransomware attacks.
The US has been keen to bring REvil to justice over the attacks that hit its infrastructure, offering rewards of $10m for information on its members.
It is unlikely though that any of the suspects will face extradition to the US.
Recommended
- Ukrainian website defacements were ‘cover for more destructive actions’
- Sales of fake vaccine certificates surge during omicron wave
- Doubts face UK businesses looking to get proactive about cybersecurity
The Kaseya attack was a landmark incident in a remarkable year for ransomware. By hitting a major supplier of third-party software, REvil was able to hit potentially thousands of organisations. The hackers then demanded $70 million in bitcoins for a universal decryptor.
Despite being linked to some of the biggest cyber-attacks of 2021, the past few months have not been easy for REvil. The group’s portal on the dark web was taken down in the summer, preventing REvil from taking ransomware payments.
The timing has sparked speculation about the reason for the move – it came at the same time as a call between US President Joe Biden and Russian President Vladimir Putin. With cybersecurity on the agenda, analysts speculated that Russian authorities had taken action to curb a rogue element operating on the country’s soil.
However, an individual claiming to represent REvil later claimed that they shut down operations after believing a group member had been arrested.
While the portal returned two months later, there was one final twist in REvil’s fortunes. The group accidentally leaked a decryptor for the Kaseya ransomware.





