LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0496: REvil

REvil is a ransomware family that has been linked to the GOLD SOUTHFIELD group and operated as ransomware-as-a-service (RaaS) since at least April 2019. REvil, which as been used against organizations in the manufacturing, transportation, and electric sectors, is highly configurable and shares code similarities with the GandCrab RaaS.[1][2][3]

EnterpriseS0496MalwareObject v2.3Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

REvil is a Windows ransomware family described by ATT&CK as a configurable ransomware-as-a-service operation since at least April 2019, linked to GOLD SOUTHFIELD and used in activity affecting manufacturing, transportation, and electric-sector organizations. Its business significance is not only encryption: the ATT&CK relationships show behaviors tied to execution, discovery, stealth, exfiltration, remote services, service stopping, and ICS-relevant loss of productivity and revenue. Leaders should treat REvil coverage as a practical test of ransomware resilience across endpoints, identity, remote access, backups, incident response, and operational continuity.

Executive priority

Prioritize REvil as a resilience and readiness scenario rather than a single malware signature. The supplied ATT&CK context connects it to financially motivated groups, RaaS operations, Windows environments, and sectors where IT disruption can affect operational productivity. Executives should ask whether the organization can prove: critical Windows systems are monitored, privileged/domain group discovery is visible, remote service use is controlled, service-stopping activity is investigated quickly, exfiltration over common channels is detectable, and recovery plans cover manufacturing, transportation, electric, or other operational dependencies where relevant.

Technical view

SOC and IR teams should validate coverage against the related ATT&CK behaviors: PowerShell, Windows Command Shell, Visual Basic, WMI execution, process injection, registry queries, system service discovery, domain group discovery, masquerading, encoded or fileless storage, exfiltration over C2 channels, remote services, and service stop activity. Because ATT&CK provides no official detection text for this software object, detection engineering should be behavior-led and mapped to the associated techniques rather than relying only on malware names such as REvil, Sodin, or Sodinokibi.

Likely telemetry

  • Windows endpoint process creation and command-line telemetry
  • PowerShell script block, module, and operational logs where available
  • WMI activity logs and remote execution evidence
  • Windows Registry access and modification telemetry
  • Service control events, service stop events, and system service inventory changes

Detection direction

  • Build detections around chains of behavior: script or shell execution followed by discovery, registry queries, service enumeration, remote service use, service stopping, suspicious file activity, and outbound transfer patterns.
  • Tune administrative-tool detections carefully because PowerShell, WMI, command shell, service control, and remote services have legitimate uses; prioritize unusual parent-child processes, new hosts, unusual accounts, off-hours execution, or activity against high-value systems.
  • Validate visibility for stealth-related behaviors in the relationships, including process injection, encoded files, fileless storage, and masquerading with legitimate resource names or locations.
  • Correlate endpoint and identity telemetry for domain group discovery, especially where enumeration precedes lateral movement or privilege-focused activity.
  • For environments with operational technology dependencies, test whether SOC workflows can connect Windows ransomware behavior to ICS impacts such as service disruption, loss of productivity, or operational information theft.

Mitigation priorities

  • Start with resilience controls: tested offline or protected backups, recovery runbooks, and business-continuity plans for Windows-dependent operations.
  • Reduce execution risk by hardening and monitoring script interpreters and administrative execution paths such as PowerShell, command shell, Visual Basic, and WMI.
  • Limit blast radius through least privilege, privileged group governance, domain group monitoring, and segmentation between user, server, and operational environments where applicable.
  • Control and monitor remote services used for administration or lateral movement, with strong authentication and logging.
  • Protect critical services from unauthorized stopping or tampering and ensure alerts for service disruption are routed to responders with business context.
Additional notes and limits

This take is based on ATT&CK S0496 REvil, its official description, external references, and supplied relationships. The object is a malware/software entry for Windows, with no official ATT&CK detection guidance. Relationships link REvil to GOLD SOUTHFIELD and FIN7 and to both enterprise and ICS techniques, including impact-relevant ICS behaviors. Local validation should determine which related techniques are relevant to the organization’s architecture and which telemetry sources are actually retained and searchable.

The supplied ATT&CK fields do not provide current activity claims, detailed procedures, indicators of compromise, guaranteed detections, or environment-specific impact. Tactics for the malware object itself are not specified, and several relationship descriptions are truncated. Any prioritization should be confirmed against local asset criticality, identity architecture, remote access exposure, backup maturity, and sector-specific operational dependencies.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

REvil

REvil is a ransomware family that has been linked to the GOLD SOUTHFIELD group and operated as ransomware-as-a-service (RaaS) since at least April 2019. REvil, which as been used against organizations in the manufacturing, transportation, and electric sectors, is highly configurable and shares code similarities with the GandCrab RaaS.[1][2][3]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

35 rows
DomainIDNameRelationship / procedure
EnterpriseT1486Data Encrypted for Impact

REvil can encrypt files on victim systems and demands a ransom to decrypt the files.[4][5][6][7][2][8][1][9]

EnterpriseT1059.003Windows Command ShellSub-technique

REvil can use the Windows command line to delete volume shadow copies and disable recovery.[5][6][8][1]

EnterpriseT1059.001PowerShellSub-technique

REvil has used PowerShell to delete volume shadow copies and download files.[10][6][2][3]

EnterpriseT1573.002Asymmetric CryptographySub-technique

REvil has encrypted C2 communications with the ECIES algorithm.[4]

EnterpriseT1055Process Injection

REvil can inject itself into running processes on a compromised host.[7]

EnterpriseT1036.005Match Legitimate Resource Name or LocationSub-technique

REvil can mimic the names of known executables.[8]

EnterpriseT1112Modify Registry

REvil can modify the Registry to save encryption parameters and system information.[5][10][11][2][1]

EnterpriseT1485Data Destruction

REvil has the capability to destroy files and folders.[4][10][11][11][2][8][1]

EnterpriseT1012Query Registry

REvil can query the Registry to get random file extensions to append to encrypted files.[1]

EnterpriseT1059.005Visual BasicSub-technique

REvil has used obfuscated VBA macros for execution.[12][8]

EnterpriseT1041Exfiltration Over C2 Channel

REvil can exfiltrate host and malware information to C2 servers.[1]

EnterpriseT1489Service Stop

REvil has the capability to stop services and kill processes.[2][1]

EnterpriseT1082System Information Discovery

REvil can identify the username, machine name, system language, keyboard layout, and OS version on a compromised host.[4][5][10][11][11][2][3][1]

EnterpriseT1106Native API

REvil can use Native API for execution and to retrieve active services.[1][2]

EnterpriseT1204.002Malicious FileSub-technique

REvil has been executed via malicious MS Word e-mail attachments.[12][7][8]

EnterpriseT1134.002Create Process with TokenSub-technique

REvil can launch an instance of itself with administrative rights using runas.[1]

EnterpriseT1685Disable or Modify Tools

REvil can connect to and disable the Symantec server on the victim's network.[5]

EnterpriseT1480.002Mutual ExclusionSub-technique

REvil attempts to create a mutex using a hard-coded value to ensure that no other instances of itself are running on the host.[17]

EnterpriseT1083File and Directory Discovery

REvil has the ability to identify specific files and directories that are not to be encrypted.[4][5][10][11][2][1]

EnterpriseT1027.013Encrypted/Encoded FileSub-technique

REvil has used encrypted strings and configuration files.[12][10][11][2][3][8][1]

EnterpriseT1189Drive-by Compromise

REvil has infected victim machines through compromised websites and exploit kits.[1][11][8][10]

EnterpriseT1007System Service Discovery

REvil can enumerate active services.[2]

EnterpriseT1047Windows Management Instrumentation

REvil can use WMI to monitor for and kill specific processes listed in its configuration file.[10][3]

EnterpriseT1140Deobfuscate/Decode Files or Information

REvil can decode encrypted strings to enable execution of commands and payloads.[12][4][5][11][2][1]

EnterpriseT1566.001Spearphishing AttachmentSub-technique

REvil has been distributed via malicious e-mail attachments including MS Word Documents.[12][5][1][11][8]

EnterpriseT1105Ingress Tool Transfer

REvil can download a copy of itself from an attacker controlled IP address to the victim machine.[6][11][8]

EnterpriseT1688Safe Mode Boot

REvil can force a reboot in safe mode with networking.[18]

EnterpriseT1680Local Storage Discovery

REvil can identify system drive information on a compromised host.[4][5][10][11][11][2][3][1]

EnterpriseT1614.001System Language DiscoverySub-technique

REvil can check the system language using GetUserDefaultUILanguage and GetSystemDefaultUILanguage. If the language is found in the list, the process terminates.[4]

EnterpriseT1134.001Token Impersonation/TheftSub-technique

REvil can obtain the token from the user that launched the explorer.exe process to avoid affecting the desktop of the SYSTEM user.[11]

EnterpriseT1071.001Web ProtocolsSub-technique

REvil has used HTTP and HTTPS in communication with C2.[5][10][11][2][1]

EnterpriseT1069.002Domain GroupsSub-technique

REvil can identify the domain membership of a compromised host.[4][11][1]

EnterpriseT1070.004File DeletionSub-technique

REvil can mark its binary code for deletion after reboot.[2]

EnterpriseT1490Inhibit System Recovery

REvil can use vssadmin to delete volume shadow copies and bcdedit to disable recovery features.[4][5][10][6][11][2][8][1][9]

EnterpriseT1027.011Fileless StorageSub-technique

REvil can save encryption parameters and system information in the Registry.[5][10][11][2][1]

Associated objects

Groups, software, and campaigns

GroupEnterprise

G0046: FIN7

FIN7 is a financially-motivated threat group that has been active since 2013. FIN7 has targeted the retail, restaurant, hospitality, software, consulting, financial services, medical equipment, cloud services, media, food and beverage, transportation, pharmaceutical, and utilities industries in the United States. A portion of FIN7 was operated out of a front company called Combi Security and often used point-of-sale malware for targeting efforts. Since 2020, FIN7 shifted operations to big game hunting (BGH), including use of REvil ransomware and their own Ransomware-as-a-Service (RaaS), Darkside. FIN7 may be linked to the Carbanak Group, but multiple threat groups have been observed using Carbanak, leading these groups to be tracked separately.[1][2][3][4][5][6][7]

GroupEnterprise

G0115: GOLD SOUTHFIELD

GOLD SOUTHFIELD is a financially motivated threat group active since at least 2018 that operates the REvil Ransomware-as-a Service (RaaS). GOLD SOUTHFIELD provides backend infrastructure for affiliates recruited on underground forums to perpetrate high value deployments. By early 2020, GOLD SOUTHFIELD started capitalizing on the new trend of stealing data and further extorting the victim to pay for their data to not get publicly leaked.[1][2][3][4]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
2.3
Created
Modified
Raw hash
9956d73492ac6a37...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.12.3Current bundle9956d73492ac…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Secureworks REvil September 2019

    Counter Threat Unit Research Team. (2019, September 24). REvil/Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  2. [2]
    Intel 471 REvil March 2020

    Intel 471 Malware Intelligence team. (2020, March 31). REvil Ransomware-as-a-Service – An analysis of a ransomware affiliate operation. Retrieved August 4, 2020.

    Open source URL
  3. [3]
    Group IB Ransomware May 2020

    Group IB. (2020, May). Ransomware Uncovered: Attackers’ Latest Methods. Retrieved August 5, 2020.

    Open source URL
  4. [4]
    Kaspersky Sodin July 2019

    Mamedov, O, et al. (2019, July 3). Sodin ransomware exploits Windows vulnerability and processor architecture. Retrieved August 4, 2020.

    Open source URL
  5. [5]
    Cylance Sodinokibi July 2019

    Cylance. (2019, July 3). hreat Spotlight: Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  6. [6]
    Talos Sodinokibi April 2019

    Cadieux, P, et al (2019, April 30). Sodinokibi ransomware exploits WebLogic Server vulnerability. Retrieved August 4, 2020.

    Open source URL
  7. [7]
    McAfee REvil October 2019

    Saavedra-Morales, J, et al. (2019, October 20). McAfee ATR Analyzes Sodinokibi aka REvil Ransomware-as-a-Service – Crescendo. Retrieved August 5, 2020.

    Open source URL
  8. [8]
    Picus Sodinokibi January 2020

    Ozarslan, S. (2020, January 15). A Brief History of Sodinokibi. Retrieved August 5, 2020.

    Open source URL
  9. [9]
    Tetra Defense Sodinokibi March 2020

    Tetra Defense. (2020, March). CAUSE AND EFFECT: SODINOKIBI RANSOMWARE ANALYSIS. Retrieved November 17, 2024.

    Open source URL
  10. [10]
    Secureworks GandCrab and REvil September 2019

    Secureworks . (2019, September 24). REvil: The GandCrab Connection. Retrieved August 4, 2020.

    Open source URL
  11. [11]
    McAfee Sodinokibi October 2019

    McAfee. (2019, October 2). McAfee ATR Analyzes Sodinokibi aka REvil Ransomware-as-a-Service – What The Code Tells Us. Retrieved August 4, 2020.

    Open source URL
  12. [12]
    G Data Sodinokibi June 2019

    Han, Karsten. (2019, June 4). Strange Bits: Sodinokibi Spam, CinaRAT, and Fake G DATA. Retrieved August 4, 2020.

    Open source URL
  13. [13]
    IBM Ransomware Trends September 2020

    Singleton, C. and Kiefer, C. (2020, September 28). Ransomware 2020: Attack Trends Affecting Organizations Worldwide. Retrieved September 20, 2021.

    Open source URL
  14. [14]
    CrowdStrike Carbon Spider August 2021

    Loui, E. and Reynolds, J. (2021, August 30). CARBON SPIDER Embraces Big Game Hunting, Part 1. Retrieved September 20, 2021.

    Open source URL
  15. [15]
    FBI Flash FIN7 USB

    The Record. (2022, January 7). FBI: FIN7 hackers target US companies with BadUSB devices to install ransomware. Retrieved January 14, 2022.

    Open source URL
  16. [16]
    Microsoft Ransomware as a Service

    Microsoft. (2022, May 9). Ransomware as a service: Understanding the cybercrime gig economy and how to protect yourself. Retrieved March 10, 2023.

    Open source URL
  17. [17]
    SecureWorks September 2019

    SecureWorks 2019, September 24 REvil/Sodinokibi Ransomware Retrieved. 2021/04/12

    Open source URL
  18. [18]
    BleepingComputer REvil 2021

    Abrams, L. (2021, March 19). REvil ransomware has a new ‘Windows Safe Mode’ encryption mode. Retrieved June 23, 2021.

    Open source URL
  19. [19]
    Cylance Sodinokibi July 2019

    Cylance. (2019, July 3). hreat Spotlight: Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  20. [20]
    Cylance Sodinokibi July 2019

    Cylance. (2019, July 3). hreat Spotlight: Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  21. [21]
    G Data Sodinokibi June 2019

    Han, Karsten. (2019, June 4). Strange Bits: Sodinokibi Spam, CinaRAT, and Fake G DATA. Retrieved August 4, 2020.

    Open source URL
  22. [22]
    G Data Sodinokibi June 2019

    Han, Karsten. (2019, June 4). Strange Bits: Sodinokibi Spam, CinaRAT, and Fake G DATA. Retrieved August 4, 2020.

    Open source URL
  23. [23]
    Group IB Ransomware May 2020

    Group IB. (2020, May). Ransomware Uncovered: Attackers’ Latest Methods. Retrieved August 5, 2020.

    Open source URL
  24. [24]
    Group IB Ransomware May 2020

    Group IB. (2020, May). Ransomware Uncovered: Attackers’ Latest Methods. Retrieved August 5, 2020.

    Open source URL
  25. [25]
    Intel 471 REvil March 2020

    Intel 471 Malware Intelligence team. (2020, March 31). REvil Ransomware-as-a-Service – An analysis of a ransomware affiliate operation. Retrieved August 4, 2020.

    Open source URL
  26. [26]
    Intel 471 REvil March 2020

    Intel 471 Malware Intelligence team. (2020, March 31). REvil Ransomware-as-a-Service – An analysis of a ransomware affiliate operation. Retrieved August 4, 2020.

    Open source URL
  27. [27]
    Kaspersky Sodin July 2019

    Mamedov, O, et al. (2019, July 3). Sodin ransomware exploits Windows vulnerability and processor architecture. Retrieved August 4, 2020.

    Open source URL
  28. [28]
    Kaspersky Sodin July 2019

    Mamedov, O, et al. (2019, July 3). Sodin ransomware exploits Windows vulnerability and processor architecture. Retrieved August 4, 2020.

    Open source URL
  29. [29]
    McAfee REvil October 2019

    Saavedra-Morales, J, et al. (2019, October 20). McAfee ATR Analyzes Sodinokibi aka REvil Ransomware-as-a-Service – Crescendo. Retrieved August 5, 2020.

    Open source URL
  30. [30]
    McAfee REvil October 2019

    Saavedra-Morales, J, et al. (2019, October 20). McAfee ATR Analyzes Sodinokibi aka REvil Ransomware-as-a-Service – Crescendo. Retrieved August 5, 2020.

    Open source URL
  31. [31]
    McAfee Sodinokibi October 2019

    McAfee. (2019, October 2). McAfee ATR Analyzes Sodinokibi aka REvil Ransomware-as-a-Service – What The Code Tells Us. Retrieved August 4, 2020.

    Open source URL
  32. [32]
    McAfee Sodinokibi October 2019

    McAfee. (2019, October 2). McAfee ATR Analyzes Sodinokibi aka REvil Ransomware-as-a-Service – What The Code Tells Us. Retrieved August 4, 2020.

    Open source URL
  33. [33]
    Picus Sodinokibi January 2020

    Ozarslan, S. (2020, January 15). A Brief History of Sodinokibi. Retrieved August 5, 2020.

    Open source URL
  34. [34]
    Picus Sodinokibi January 2020

    Ozarslan, S. (2020, January 15). A Brief History of Sodinokibi. Retrieved August 5, 2020.

    Open source URL
  35. [35]
    Secureworks GandCrab and REvil September 2019

    Secureworks . (2019, September 24). REvil: The GandCrab Connection. Retrieved August 4, 2020.

    Open source URL
  36. [36]
    Secureworks GandCrab and REvil September 2019

    Secureworks . (2019, September 24). REvil: The GandCrab Connection. Retrieved August 4, 2020.

    Open source URL
  37. [37]
    Secureworks REvil September 2019

    Counter Threat Unit Research Team. (2019, September 24). REvil/Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  38. [38]
    Secureworks REvil September 2019

    Counter Threat Unit Research Team. (2019, September 24). REvil/Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  39. [39]
    Sodin

    (Citation: Intel 471 REvil March 2020)(Citation: Kaspersky Sodin July 2019)

  40. [40]
    Sodin

    (Citation: Intel 471 REvil March 2020)(Citation: Kaspersky Sodin July 2019)

  41. [41]
    Sodin

    (Citation: Intel 471 REvil March 2020)(Citation: Kaspersky Sodin July 2019)

  42. [42]
    Sodinokibi

    (Citation: Secureworks REvil September 2019)(Citation: Intel 471 REvil March 2020)(Citation: G Data Sodinokibi June 2019)(Citation: Kaspersky Sodin July 2019)(Citation: Cylance Sodinokibi July 2019)(Citation: Secureworks GandCrab and REvil September 2019)(Citation: Talos Sodinokibi April 2019)(Citation: McAfee Sodinokibi October 2019)(Citation: McAfee REvil October 2019)(Citation: Picus Sodinokibi January 2020)(Citation: Secureworks REvil September 2019)(Citation: Tetra Defense Sodinokibi March 2020)

  43. [43]
    Sodinokibi

    (Citation: Secureworks REvil September 2019)(Citation: Intel 471 REvil March 2020)(Citation: G Data Sodinokibi June 2019)(Citation: Kaspersky Sodin July 2019)(Citation: Cylance Sodinokibi July 2019)(Citation: Secureworks GandCrab and REvil September 2019)(Citation: Talos Sodinokibi April 2019)(Citation: McAfee Sodinokibi October 2019)(Citation: McAfee REvil October 2019)(Citation: Picus Sodinokibi January 2020)(Citation: Secureworks REvil September 2019)(Citation: Tetra Defense Sodinokibi March 2020)

  44. [44]
    Sodinokibi

    (Citation: Secureworks REvil September 2019)(Citation: Intel 471 REvil March 2020)(Citation: G Data Sodinokibi June 2019)(Citation: Kaspersky Sodin July 2019)(Citation: Cylance Sodinokibi July 2019)(Citation: Secureworks GandCrab and REvil September 2019)(Citation: Talos Sodinokibi April 2019)(Citation: McAfee Sodinokibi October 2019)(Citation: McAfee REvil October 2019)(Citation: Picus Sodinokibi January 2020)(Citation: Secureworks REvil September 2019)(Citation: Tetra Defense Sodinokibi March 2020)

  45. [45]
    Talos Sodinokibi April 2019

    Cadieux, P, et al (2019, April 30). Sodinokibi ransomware exploits WebLogic Server vulnerability. Retrieved August 4, 2020.

    Open source URL
  46. [46]
    Talos Sodinokibi April 2019

    Cadieux, P, et al (2019, April 30). Sodinokibi ransomware exploits WebLogic Server vulnerability. Retrieved August 4, 2020.

    Open source URL
  47. [47]
    Tetra Defense Sodinokibi March 2020

    Tetra Defense. (2020, March). CAUSE AND EFFECT: SODINOKIBI RANSOMWARE ANALYSIS. Retrieved November 17, 2024.

    Open source URL
  48. [48]
    Tetra Defense Sodinokibi March 2020

    Tetra Defense. (2020, March). CAUSE AND EFFECT: SODINOKIBI RANSOMWARE ANALYSIS. Retrieved November 17, 2024.

    Open source URL
  49. [49]
    mitre-attackS0496
    Open source URL
  50. [50]
    mitre-attackS0496
    Open source URL
  51. [51]
    mitre-attackS0496
    Open source URL
  52. [52]
    Cylance Sodinokibi July 2019

    Cylance. (2019, July 3). hreat Spotlight: Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  53. [53]
    Cylance Sodinokibi July 2019

    Cylance. (2019, July 3). hreat Spotlight: Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  54. [54]
    Intel 471 REvil March 2020

    Intel 471 Malware Intelligence team. (2020, March 31). REvil Ransomware-as-a-Service – An analysis of a ransomware affiliate operation. Retrieved August 4, 2020.

    Open source URL
  55. [55]
    Intel 471 REvil March 2020

    Intel 471 Malware Intelligence team. (2020, March 31). REvil Ransomware-as-a-Service – An analysis of a ransomware affiliate operation. Retrieved August 4, 2020.

    Open source URL
  56. [56]
    Kaspersky Sodin July 2019

    Mamedov, O, et al. (2019, July 3). Sodin ransomware exploits Windows vulnerability and processor architecture. Retrieved August 4, 2020.

    Open source URL
  57. [57]
    Kaspersky Sodin July 2019

    Mamedov, O, et al. (2019, July 3). Sodin ransomware exploits Windows vulnerability and processor architecture. Retrieved August 4, 2020.

    Open source URL
  58. [58]
    McAfee REvil October 2019

    Saavedra-Morales, J, et al. (2019, October 20). McAfee ATR Analyzes Sodinokibi aka REvil Ransomware-as-a-Service – Crescendo. Retrieved August 5, 2020.

    Open source URL
  59. [59]
    McAfee REvil October 2019

    Saavedra-Morales, J, et al. (2019, October 20). McAfee ATR Analyzes Sodinokibi aka REvil Ransomware-as-a-Service – Crescendo. Retrieved August 5, 2020.

    Open source URL
  60. [60]
    Picus Sodinokibi January 2020

    Ozarslan, S. (2020, January 15). A Brief History of Sodinokibi. Retrieved August 5, 2020.

    Open source URL
  61. [61]
    Picus Sodinokibi January 2020

    Ozarslan, S. (2020, January 15). A Brief History of Sodinokibi. Retrieved August 5, 2020.

    Open source URL
  62. [62]
    Secureworks REvil September 2019

    Counter Threat Unit Research Team. (2019, September 24). REvil/Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  63. [63]
    Secureworks REvil September 2019

    Counter Threat Unit Research Team. (2019, September 24). REvil/Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  64. [64]
    Talos Sodinokibi April 2019

    Cadieux, P, et al (2019, April 30). Sodinokibi ransomware exploits WebLogic Server vulnerability. Retrieved August 4, 2020.

    Open source URL
  65. [65]
    Talos Sodinokibi April 2019

    Cadieux, P, et al (2019, April 30). Sodinokibi ransomware exploits WebLogic Server vulnerability. Retrieved August 4, 2020.

    Open source URL
  66. [66]
    Tetra Defense Sodinokibi March 2020

    Tetra Defense. (2020, March). CAUSE AND EFFECT: SODINOKIBI RANSOMWARE ANALYSIS. Retrieved November 17, 2024.

    Open source URL
  67. [67]
    Tetra Defense Sodinokibi March 2020

    Tetra Defense. (2020, March). CAUSE AND EFFECT: SODINOKIBI RANSOMWARE ANALYSIS. Retrieved November 17, 2024.

    Open source URL
  68. [68]
    Cylance Sodinokibi July 2019

    Cylance. (2019, July 3). hreat Spotlight: Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  69. [69]
    Cylance Sodinokibi July 2019

    Cylance. (2019, July 3). hreat Spotlight: Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  70. [70]
    Picus Sodinokibi January 2020

    Ozarslan, S. (2020, January 15). A Brief History of Sodinokibi. Retrieved August 5, 2020.

    Open source URL
  71. [71]
    Picus Sodinokibi January 2020

    Ozarslan, S. (2020, January 15). A Brief History of Sodinokibi. Retrieved August 5, 2020.

    Open source URL
  72. [72]
    Secureworks REvil September 2019

    Counter Threat Unit Research Team. (2019, September 24). REvil/Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  73. [73]
    Secureworks REvil September 2019

    Counter Threat Unit Research Team. (2019, September 24). REvil/Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  74. [74]
    Talos Sodinokibi April 2019

    Cadieux, P, et al (2019, April 30). Sodinokibi ransomware exploits WebLogic Server vulnerability. Retrieved August 4, 2020.

    Open source URL
  75. [75]
    Talos Sodinokibi April 2019

    Cadieux, P, et al (2019, April 30). Sodinokibi ransomware exploits WebLogic Server vulnerability. Retrieved August 4, 2020.

    Open source URL
  76. [76]
    Group IB Ransomware May 2020

    Group IB. (2020, May). Ransomware Uncovered: Attackers’ Latest Methods. Retrieved August 5, 2020.

    Open source URL
  77. [77]
    Group IB Ransomware May 2020

    Group IB. (2020, May). Ransomware Uncovered: Attackers’ Latest Methods. Retrieved August 5, 2020.

    Open source URL
  78. [78]
    Intel 471 REvil March 2020

    Intel 471 Malware Intelligence team. (2020, March 31). REvil Ransomware-as-a-Service – An analysis of a ransomware affiliate operation. Retrieved August 4, 2020.

    Open source URL
  79. [79]
    Intel 471 REvil March 2020

    Intel 471 Malware Intelligence team. (2020, March 31). REvil Ransomware-as-a-Service – An analysis of a ransomware affiliate operation. Retrieved August 4, 2020.

    Open source URL
  80. [80]
    Secureworks GandCrab and REvil September 2019

    Secureworks . (2019, September 24). REvil: The GandCrab Connection. Retrieved August 4, 2020.

    Open source URL
  81. [81]
    Secureworks GandCrab and REvil September 2019

    Secureworks . (2019, September 24). REvil: The GandCrab Connection. Retrieved August 4, 2020.

    Open source URL
  82. [82]
    Talos Sodinokibi April 2019

    Cadieux, P, et al (2019, April 30). Sodinokibi ransomware exploits WebLogic Server vulnerability. Retrieved August 4, 2020.

    Open source URL
  83. [83]
    Talos Sodinokibi April 2019

    Cadieux, P, et al (2019, April 30). Sodinokibi ransomware exploits WebLogic Server vulnerability. Retrieved August 4, 2020.

    Open source URL
  84. [84]
    Kaspersky Sodin July 2019

    Mamedov, O, et al. (2019, July 3). Sodin ransomware exploits Windows vulnerability and processor architecture. Retrieved August 4, 2020.

    Open source URL
  85. [85]
    Kaspersky Sodin July 2019

    Mamedov, O, et al. (2019, July 3). Sodin ransomware exploits Windows vulnerability and processor architecture. Retrieved August 4, 2020.

    Open source URL
  86. [86]
    McAfee REvil October 2019

    Saavedra-Morales, J, et al. (2019, October 20). McAfee ATR Analyzes Sodinokibi aka REvil Ransomware-as-a-Service – Crescendo. Retrieved August 5, 2020.

    Open source URL
  87. [87]
    McAfee REvil October 2019

    Saavedra-Morales, J, et al. (2019, October 20). McAfee ATR Analyzes Sodinokibi aka REvil Ransomware-as-a-Service – Crescendo. Retrieved August 5, 2020.

    Open source URL
  88. [88]
    Picus Sodinokibi January 2020

    Ozarslan, S. (2020, January 15). A Brief History of Sodinokibi. Retrieved August 5, 2020.

    Open source URL
  89. [89]
    Picus Sodinokibi January 2020

    Ozarslan, S. (2020, January 15). A Brief History of Sodinokibi. Retrieved August 5, 2020.

    Open source URL
  90. [90]
    Cylance Sodinokibi July 2019

    Cylance. (2019, July 3). hreat Spotlight: Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  91. [91]
    Cylance Sodinokibi July 2019

    Cylance. (2019, July 3). hreat Spotlight: Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  92. [92]
    Intel 471 REvil March 2020

    Intel 471 Malware Intelligence team. (2020, March 31). REvil Ransomware-as-a-Service – An analysis of a ransomware affiliate operation. Retrieved August 4, 2020.

    Open source URL
  93. [93]
    Intel 471 REvil March 2020

    Intel 471 Malware Intelligence team. (2020, March 31). REvil Ransomware-as-a-Service – An analysis of a ransomware affiliate operation. Retrieved August 4, 2020.

    Open source URL
  94. [94]
    McAfee Sodinokibi October 2019

    McAfee. (2019, October 2). McAfee ATR Analyzes Sodinokibi aka REvil Ransomware-as-a-Service – What The Code Tells Us. Retrieved August 4, 2020.

    Open source URL
  95. [95]
    McAfee Sodinokibi October 2019

    McAfee. (2019, October 2). McAfee ATR Analyzes Sodinokibi aka REvil Ransomware-as-a-Service – What The Code Tells Us. Retrieved August 4, 2020.

    Open source URL
  96. [96]
    Secureworks GandCrab and REvil September 2019

    Secureworks . (2019, September 24). REvil: The GandCrab Connection. Retrieved August 4, 2020.

    Open source URL
  97. [97]
    Secureworks GandCrab and REvil September 2019

    Secureworks . (2019, September 24). REvil: The GandCrab Connection. Retrieved August 4, 2020.

    Open source URL
  98. [98]
    Secureworks REvil September 2019

    Counter Threat Unit Research Team. (2019, September 24). REvil/Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  99. [99]
    Secureworks REvil September 2019

    Counter Threat Unit Research Team. (2019, September 24). REvil/Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  100. [100]
    Intel 471 REvil March 2020

    Intel 471 Malware Intelligence team. (2020, March 31). REvil Ransomware-as-a-Service – An analysis of a ransomware affiliate operation. Retrieved August 4, 2020.

    Open source URL
  101. [101]
    Intel 471 REvil March 2020

    Intel 471 Malware Intelligence team. (2020, March 31). REvil Ransomware-as-a-Service – An analysis of a ransomware affiliate operation. Retrieved August 4, 2020.

    Open source URL
  102. [102]
    Kaspersky Sodin July 2019

    Mamedov, O, et al. (2019, July 3). Sodin ransomware exploits Windows vulnerability and processor architecture. Retrieved August 4, 2020.

    Open source URL
  103. [103]
    Kaspersky Sodin July 2019

    Mamedov, O, et al. (2019, July 3). Sodin ransomware exploits Windows vulnerability and processor architecture. Retrieved August 4, 2020.

    Open source URL
  104. [104]
    McAfee Sodinokibi October 2019

    McAfee. (2019, October 2). McAfee ATR Analyzes Sodinokibi aka REvil Ransomware-as-a-Service – What The Code Tells Us. Retrieved August 4, 2020.

    Open source URL
  105. [105]
    McAfee Sodinokibi October 2019

    McAfee. (2019, October 2). McAfee ATR Analyzes Sodinokibi aka REvil Ransomware-as-a-Service – What The Code Tells Us. Retrieved August 4, 2020.

    Open source URL
  106. [106]
    McAfee Sodinokibi October 2019

    McAfee. (2019, October 2). McAfee ATR Analyzes Sodinokibi aka REvil Ransomware-as-a-Service – What The Code Tells Us. Retrieved August 4, 2020.

    Open source URL
  107. [107]
    McAfee Sodinokibi October 2019

    McAfee. (2019, October 2). McAfee ATR Analyzes Sodinokibi aka REvil Ransomware-as-a-Service – What The Code Tells Us. Retrieved August 4, 2020.

    Open source URL
  108. [108]
    Picus Sodinokibi January 2020

    Ozarslan, S. (2020, January 15). A Brief History of Sodinokibi. Retrieved August 5, 2020.

    Open source URL
  109. [109]
    Picus Sodinokibi January 2020

    Ozarslan, S. (2020, January 15). A Brief History of Sodinokibi. Retrieved August 5, 2020.

    Open source URL
  110. [110]
    Secureworks GandCrab and REvil September 2019

    Secureworks . (2019, September 24). REvil: The GandCrab Connection. Retrieved August 4, 2020.

    Open source URL
  111. [111]
    Secureworks GandCrab and REvil September 2019

    Secureworks . (2019, September 24). REvil: The GandCrab Connection. Retrieved August 4, 2020.

    Open source URL
  112. [112]
    Secureworks REvil September 2019

    Counter Threat Unit Research Team. (2019, September 24). REvil/Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  113. [113]
    Secureworks REvil September 2019

    Counter Threat Unit Research Team. (2019, September 24). REvil/Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  114. [114]
    Secureworks REvil September 2019

    Counter Threat Unit Research Team. (2019, September 24). REvil/Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  115. [115]
    Secureworks REvil September 2019

    Counter Threat Unit Research Team. (2019, September 24). REvil/Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  116. [116]
    G Data Sodinokibi June 2019

    Han, Karsten. (2019, June 4). Strange Bits: Sodinokibi Spam, CinaRAT, and Fake G DATA. Retrieved August 4, 2020.

    Open source URL
  117. [117]
    G Data Sodinokibi June 2019

    Han, Karsten. (2019, June 4). Strange Bits: Sodinokibi Spam, CinaRAT, and Fake G DATA. Retrieved August 4, 2020.

    Open source URL
  118. [118]
    Picus Sodinokibi January 2020

    Ozarslan, S. (2020, January 15). A Brief History of Sodinokibi. Retrieved August 5, 2020.

    Open source URL
  119. [119]
    Picus Sodinokibi January 2020

    Ozarslan, S. (2020, January 15). A Brief History of Sodinokibi. Retrieved August 5, 2020.

    Open source URL
  120. [120]
    Secureworks REvil September 2019

    Counter Threat Unit Research Team. (2019, September 24). REvil/Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  121. [121]
    Secureworks REvil September 2019

    Counter Threat Unit Research Team. (2019, September 24). REvil/Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  122. [122]
    Intel 471 REvil March 2020

    Intel 471 Malware Intelligence team. (2020, March 31). REvil Ransomware-as-a-Service – An analysis of a ransomware affiliate operation. Retrieved August 4, 2020.

    Open source URL
  123. [123]
    Intel 471 REvil March 2020

    Intel 471 Malware Intelligence team. (2020, March 31). REvil Ransomware-as-a-Service – An analysis of a ransomware affiliate operation. Retrieved August 4, 2020.

    Open source URL
  124. [124]
    Secureworks REvil September 2019

    Counter Threat Unit Research Team. (2019, September 24). REvil/Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  125. [125]
    Secureworks REvil September 2019

    Counter Threat Unit Research Team. (2019, September 24). REvil/Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  126. [126]
    Cylance Sodinokibi July 2019

    Cylance. (2019, July 3). hreat Spotlight: Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  127. [127]
    Cylance Sodinokibi July 2019

    Cylance. (2019, July 3). hreat Spotlight: Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  128. [128]
    Group IB Ransomware May 2020

    Group IB. (2020, May). Ransomware Uncovered: Attackers’ Latest Methods. Retrieved August 5, 2020.

    Open source URL
  129. [129]
    Group IB Ransomware May 2020

    Group IB. (2020, May). Ransomware Uncovered: Attackers’ Latest Methods. Retrieved August 5, 2020.

    Open source URL
  130. [130]
    Intel 471 REvil March 2020

    Intel 471 Malware Intelligence team. (2020, March 31). REvil Ransomware-as-a-Service – An analysis of a ransomware affiliate operation. Retrieved August 4, 2020.

    Open source URL
  131. [131]
    Intel 471 REvil March 2020

    Intel 471 Malware Intelligence team. (2020, March 31). REvil Ransomware-as-a-Service – An analysis of a ransomware affiliate operation. Retrieved August 4, 2020.

    Open source URL
  132. [132]
    Kaspersky Sodin July 2019

    Mamedov, O, et al. (2019, July 3). Sodin ransomware exploits Windows vulnerability and processor architecture. Retrieved August 4, 2020.

    Open source URL
  133. [133]
    Kaspersky Sodin July 2019

    Mamedov, O, et al. (2019, July 3). Sodin ransomware exploits Windows vulnerability and processor architecture. Retrieved August 4, 2020.

    Open source URL
  134. [134]
    McAfee Sodinokibi October 2019

    McAfee. (2019, October 2). McAfee ATR Analyzes Sodinokibi aka REvil Ransomware-as-a-Service – What The Code Tells Us. Retrieved August 4, 2020.

    Open source URL
  135. [135]
    McAfee Sodinokibi October 2019

    McAfee. (2019, October 2). McAfee ATR Analyzes Sodinokibi aka REvil Ransomware-as-a-Service – What The Code Tells Us. Retrieved August 4, 2020.

    Open source URL
  136. [136]
    Secureworks GandCrab and REvil September 2019

    Secureworks . (2019, September 24). REvil: The GandCrab Connection. Retrieved August 4, 2020.

    Open source URL
  137. [137]
    Secureworks GandCrab and REvil September 2019

    Secureworks . (2019, September 24). REvil: The GandCrab Connection. Retrieved August 4, 2020.

    Open source URL
  138. [138]
    Secureworks REvil September 2019

    Counter Threat Unit Research Team. (2019, September 24). REvil/Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  139. [139]
    Secureworks REvil September 2019

    Counter Threat Unit Research Team. (2019, September 24). REvil/Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  140. [140]
    Intel 471 REvil March 2020

    Intel 471 Malware Intelligence team. (2020, March 31). REvil Ransomware-as-a-Service – An analysis of a ransomware affiliate operation. Retrieved August 4, 2020.

    Open source URL
  141. [141]
    Intel 471 REvil March 2020

    Intel 471 Malware Intelligence team. (2020, March 31). REvil Ransomware-as-a-Service – An analysis of a ransomware affiliate operation. Retrieved August 4, 2020.

    Open source URL
  142. [142]
    Secureworks REvil September 2019

    Counter Threat Unit Research Team. (2019, September 24). REvil/Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  143. [143]
    Secureworks REvil September 2019

    Counter Threat Unit Research Team. (2019, September 24). REvil/Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  144. [144]
    G Data Sodinokibi June 2019

    Han, Karsten. (2019, June 4). Strange Bits: Sodinokibi Spam, CinaRAT, and Fake G DATA. Retrieved August 4, 2020.

    Open source URL
  145. [145]
    G Data Sodinokibi June 2019

    Han, Karsten. (2019, June 4). Strange Bits: Sodinokibi Spam, CinaRAT, and Fake G DATA. Retrieved August 4, 2020.

    Open source URL
  146. [146]
    McAfee REvil October 2019

    Saavedra-Morales, J, et al. (2019, October 20). McAfee ATR Analyzes Sodinokibi aka REvil Ransomware-as-a-Service – Crescendo. Retrieved August 5, 2020.

    Open source URL
  147. [147]
    McAfee REvil October 2019

    Saavedra-Morales, J, et al. (2019, October 20). McAfee ATR Analyzes Sodinokibi aka REvil Ransomware-as-a-Service – Crescendo. Retrieved August 5, 2020.

    Open source URL
  148. [148]
    Picus Sodinokibi January 2020

    Ozarslan, S. (2020, January 15). A Brief History of Sodinokibi. Retrieved August 5, 2020.

    Open source URL
  149. [149]
    Picus Sodinokibi January 2020

    Ozarslan, S. (2020, January 15). A Brief History of Sodinokibi. Retrieved August 5, 2020.

    Open source URL
  150. [150]
    CrowdStrike Carbon Spider August 2021

    Loui, E. and Reynolds, J. (2021, August 30). CARBON SPIDER Embraces Big Game Hunting, Part 1. Retrieved September 20, 2021.

    Open source URL
  151. [151]
    FBI Flash FIN7 USB

    The Record. (2022, January 7). FBI: FIN7 hackers target US companies with BadUSB devices to install ransomware. Retrieved January 14, 2022.

    Open source URL
  152. [152]
    IBM Ransomware Trends September 2020

    Singleton, C. and Kiefer, C. (2020, September 28). Ransomware 2020: Attack Trends Affecting Organizations Worldwide. Retrieved September 20, 2021.

    Open source URL
  153. [153]
    Microsoft Ransomware as a Service

    Microsoft. (2022, May 9). Ransomware as a service: Understanding the cybercrime gig economy and how to protect yourself. Retrieved March 10, 2023.

    Open source URL
  154. [154]
    Secureworks REvil September 2019

    Counter Threat Unit Research Team. (2019, September 24). REvil/Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  155. [155]
    Secureworks REvil September 2019

    Counter Threat Unit Research Team. (2019, September 24). REvil/Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  156. [156]
    Cylance Sodinokibi July 2019

    Cylance. (2019, July 3). hreat Spotlight: Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  157. [157]
    Cylance Sodinokibi July 2019

    Cylance. (2019, July 3). hreat Spotlight: Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  158. [158]
    SecureWorks September 2019

    SecureWorks 2019, September 24 REvil/Sodinokibi Ransomware Retrieved. 2021/04/12

    Open source URL
  159. [159]
    Cylance Sodinokibi July 2019

    Cylance. (2019, July 3). hreat Spotlight: Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  160. [160]
    Cylance Sodinokibi July 2019

    Cylance. (2019, July 3). hreat Spotlight: Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  161. [161]
    Intel 471 REvil March 2020

    Intel 471 Malware Intelligence team. (2020, March 31). REvil Ransomware-as-a-Service – An analysis of a ransomware affiliate operation. Retrieved August 4, 2020.

    Open source URL
  162. [162]
    Intel 471 REvil March 2020

    Intel 471 Malware Intelligence team. (2020, March 31). REvil Ransomware-as-a-Service – An analysis of a ransomware affiliate operation. Retrieved August 4, 2020.

    Open source URL
  163. [163]
    Kaspersky Sodin July 2019

    Mamedov, O, et al. (2019, July 3). Sodin ransomware exploits Windows vulnerability and processor architecture. Retrieved August 4, 2020.

    Open source URL
  164. [164]
    Kaspersky Sodin July 2019

    Mamedov, O, et al. (2019, July 3). Sodin ransomware exploits Windows vulnerability and processor architecture. Retrieved August 4, 2020.

    Open source URL
  165. [165]
    McAfee Sodinokibi October 2019

    McAfee. (2019, October 2). McAfee ATR Analyzes Sodinokibi aka REvil Ransomware-as-a-Service – What The Code Tells Us. Retrieved August 4, 2020.

    Open source URL
  166. [166]
    McAfee Sodinokibi October 2019

    McAfee. (2019, October 2). McAfee ATR Analyzes Sodinokibi aka REvil Ransomware-as-a-Service – What The Code Tells Us. Retrieved August 4, 2020.

    Open source URL
  167. [167]
    Secureworks GandCrab and REvil September 2019

    Secureworks . (2019, September 24). REvil: The GandCrab Connection. Retrieved August 4, 2020.

    Open source URL
  168. [168]
    Secureworks GandCrab and REvil September 2019

    Secureworks . (2019, September 24). REvil: The GandCrab Connection. Retrieved August 4, 2020.

    Open source URL
  169. [169]
    Secureworks REvil September 2019

    Counter Threat Unit Research Team. (2019, September 24). REvil/Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  170. [170]
    Secureworks REvil September 2019

    Counter Threat Unit Research Team. (2019, September 24). REvil/Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  171. [171]
    G Data Sodinokibi June 2019

    Han, Karsten. (2019, June 4). Strange Bits: Sodinokibi Spam, CinaRAT, and Fake G DATA. Retrieved August 4, 2020.

    Open source URL
  172. [172]
    G Data Sodinokibi June 2019

    Han, Karsten. (2019, June 4). Strange Bits: Sodinokibi Spam, CinaRAT, and Fake G DATA. Retrieved August 4, 2020.

    Open source URL
  173. [173]
    Group IB Ransomware May 2020

    Group IB. (2020, May). Ransomware Uncovered: Attackers’ Latest Methods. Retrieved August 5, 2020.

    Open source URL
  174. [174]
    Group IB Ransomware May 2020

    Group IB. (2020, May). Ransomware Uncovered: Attackers’ Latest Methods. Retrieved August 5, 2020.

    Open source URL
  175. [175]
    Intel 471 REvil March 2020

    Intel 471 Malware Intelligence team. (2020, March 31). REvil Ransomware-as-a-Service – An analysis of a ransomware affiliate operation. Retrieved August 4, 2020.

    Open source URL
  176. [176]
    Intel 471 REvil March 2020

    Intel 471 Malware Intelligence team. (2020, March 31). REvil Ransomware-as-a-Service – An analysis of a ransomware affiliate operation. Retrieved August 4, 2020.

    Open source URL
  177. [177]
    McAfee Sodinokibi October 2019

    McAfee. (2019, October 2). McAfee ATR Analyzes Sodinokibi aka REvil Ransomware-as-a-Service – What The Code Tells Us. Retrieved August 4, 2020.

    Open source URL
  178. [178]
    McAfee Sodinokibi October 2019

    McAfee. (2019, October 2). McAfee ATR Analyzes Sodinokibi aka REvil Ransomware-as-a-Service – What The Code Tells Us. Retrieved August 4, 2020.

    Open source URL
  179. [179]
    Picus Sodinokibi January 2020

    Ozarslan, S. (2020, January 15). A Brief History of Sodinokibi. Retrieved August 5, 2020.

    Open source URL
  180. [180]
    Picus Sodinokibi January 2020

    Ozarslan, S. (2020, January 15). A Brief History of Sodinokibi. Retrieved August 5, 2020.

    Open source URL
  181. [181]
    Secureworks GandCrab and REvil September 2019

    Secureworks . (2019, September 24). REvil: The GandCrab Connection. Retrieved August 4, 2020.

    Open source URL
  182. [182]
    Secureworks GandCrab and REvil September 2019

    Secureworks . (2019, September 24). REvil: The GandCrab Connection. Retrieved August 4, 2020.

    Open source URL
  183. [183]
    Secureworks REvil September 2019

    Counter Threat Unit Research Team. (2019, September 24). REvil/Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  184. [184]
    Secureworks REvil September 2019

    Counter Threat Unit Research Team. (2019, September 24). REvil/Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  185. [185]
    McAfee Sodinokibi October 2019

    McAfee. (2019, October 2). McAfee ATR Analyzes Sodinokibi aka REvil Ransomware-as-a-Service – What The Code Tells Us. Retrieved August 4, 2020.

    Open source URL
  186. [186]
    McAfee Sodinokibi October 2019

    McAfee. (2019, October 2). McAfee ATR Analyzes Sodinokibi aka REvil Ransomware-as-a-Service – What The Code Tells Us. Retrieved August 4, 2020.

    Open source URL
  187. [187]
    Picus Sodinokibi January 2020

    Ozarslan, S. (2020, January 15). A Brief History of Sodinokibi. Retrieved August 5, 2020.

    Open source URL
  188. [188]
    Picus Sodinokibi January 2020

    Ozarslan, S. (2020, January 15). A Brief History of Sodinokibi. Retrieved August 5, 2020.

    Open source URL
  189. [189]
    Secureworks GandCrab and REvil September 2019

    Secureworks . (2019, September 24). REvil: The GandCrab Connection. Retrieved August 4, 2020.

    Open source URL
  190. [190]
    Secureworks GandCrab and REvil September 2019

    Secureworks . (2019, September 24). REvil: The GandCrab Connection. Retrieved August 4, 2020.

    Open source URL
  191. [191]
    Secureworks REvil September 2019

    Counter Threat Unit Research Team. (2019, September 24). REvil/Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  192. [192]
    Secureworks REvil September 2019

    Counter Threat Unit Research Team. (2019, September 24). REvil/Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  193. [193]
    Intel 471 REvil March 2020

    Intel 471 Malware Intelligence team. (2020, March 31). REvil Ransomware-as-a-Service – An analysis of a ransomware affiliate operation. Retrieved August 4, 2020.

    Open source URL
  194. [194]
    Intel 471 REvil March 2020

    Intel 471 Malware Intelligence team. (2020, March 31). REvil Ransomware-as-a-Service – An analysis of a ransomware affiliate operation. Retrieved August 4, 2020.

    Open source URL
  195. [195]
    Group IB Ransomware May 2020

    Group IB. (2020, May). Ransomware Uncovered: Attackers’ Latest Methods. Retrieved August 5, 2020.

    Open source URL
  196. [196]
    Group IB Ransomware May 2020

    Group IB. (2020, May). Ransomware Uncovered: Attackers’ Latest Methods. Retrieved August 5, 2020.

    Open source URL
  197. [197]
    Secureworks GandCrab and REvil September 2019

    Secureworks . (2019, September 24). REvil: The GandCrab Connection. Retrieved August 4, 2020.

    Open source URL
  198. [198]
    Secureworks GandCrab and REvil September 2019

    Secureworks . (2019, September 24). REvil: The GandCrab Connection. Retrieved August 4, 2020.

    Open source URL
  199. [199]
    Cylance Sodinokibi July 2019

    Cylance. (2019, July 3). hreat Spotlight: Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  200. [200]
    Cylance Sodinokibi July 2019

    Cylance. (2019, July 3). hreat Spotlight: Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  201. [201]
    G Data Sodinokibi June 2019

    Han, Karsten. (2019, June 4). Strange Bits: Sodinokibi Spam, CinaRAT, and Fake G DATA. Retrieved August 4, 2020.

    Open source URL
  202. [202]
    G Data Sodinokibi June 2019

    Han, Karsten. (2019, June 4). Strange Bits: Sodinokibi Spam, CinaRAT, and Fake G DATA. Retrieved August 4, 2020.

    Open source URL
  203. [203]
    Intel 471 REvil March 2020

    Intel 471 Malware Intelligence team. (2020, March 31). REvil Ransomware-as-a-Service – An analysis of a ransomware affiliate operation. Retrieved August 4, 2020.

    Open source URL
  204. [204]
    Intel 471 REvil March 2020

    Intel 471 Malware Intelligence team. (2020, March 31). REvil Ransomware-as-a-Service – An analysis of a ransomware affiliate operation. Retrieved August 4, 2020.

    Open source URL
  205. [205]
    Kaspersky Sodin July 2019

    Mamedov, O, et al. (2019, July 3). Sodin ransomware exploits Windows vulnerability and processor architecture. Retrieved August 4, 2020.

    Open source URL
  206. [206]
    Kaspersky Sodin July 2019

    Mamedov, O, et al. (2019, July 3). Sodin ransomware exploits Windows vulnerability and processor architecture. Retrieved August 4, 2020.

    Open source URL
  207. [207]
    McAfee Sodinokibi October 2019

    McAfee. (2019, October 2). McAfee ATR Analyzes Sodinokibi aka REvil Ransomware-as-a-Service – What The Code Tells Us. Retrieved August 4, 2020.

    Open source URL
  208. [208]
    McAfee Sodinokibi October 2019

    McAfee. (2019, October 2). McAfee ATR Analyzes Sodinokibi aka REvil Ransomware-as-a-Service – What The Code Tells Us. Retrieved August 4, 2020.

    Open source URL
  209. [209]
    Secureworks REvil September 2019

    Counter Threat Unit Research Team. (2019, September 24). REvil/Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  210. [210]
    Secureworks REvil September 2019

    Counter Threat Unit Research Team. (2019, September 24). REvil/Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  211. [211]
    Cylance Sodinokibi July 2019

    Cylance. (2019, July 3). hreat Spotlight: Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  212. [212]
    Cylance Sodinokibi July 2019

    Cylance. (2019, July 3). hreat Spotlight: Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  213. [213]
    G Data Sodinokibi June 2019

    Han, Karsten. (2019, June 4). Strange Bits: Sodinokibi Spam, CinaRAT, and Fake G DATA. Retrieved August 4, 2020.

    Open source URL
  214. [214]
    G Data Sodinokibi June 2019

    Han, Karsten. (2019, June 4). Strange Bits: Sodinokibi Spam, CinaRAT, and Fake G DATA. Retrieved August 4, 2020.

    Open source URL
  215. [215]
    McAfee Sodinokibi October 2019

    McAfee. (2019, October 2). McAfee ATR Analyzes Sodinokibi aka REvil Ransomware-as-a-Service – What The Code Tells Us. Retrieved August 4, 2020.

    Open source URL
  216. [216]
    McAfee Sodinokibi October 2019

    McAfee. (2019, October 2). McAfee ATR Analyzes Sodinokibi aka REvil Ransomware-as-a-Service – What The Code Tells Us. Retrieved August 4, 2020.

    Open source URL
  217. [217]
    Picus Sodinokibi January 2020

    Ozarslan, S. (2020, January 15). A Brief History of Sodinokibi. Retrieved August 5, 2020.

    Open source URL
  218. [218]
    Picus Sodinokibi January 2020

    Ozarslan, S. (2020, January 15). A Brief History of Sodinokibi. Retrieved August 5, 2020.

    Open source URL
  219. [219]
    Secureworks REvil September 2019

    Counter Threat Unit Research Team. (2019, September 24). REvil/Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  220. [220]
    Secureworks REvil September 2019

    Counter Threat Unit Research Team. (2019, September 24). REvil/Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  221. [221]
    McAfee Sodinokibi October 2019

    McAfee. (2019, October 2). McAfee ATR Analyzes Sodinokibi aka REvil Ransomware-as-a-Service – What The Code Tells Us. Retrieved August 4, 2020.

    Open source URL
  222. [222]
    McAfee Sodinokibi October 2019

    McAfee. (2019, October 2). McAfee ATR Analyzes Sodinokibi aka REvil Ransomware-as-a-Service – What The Code Tells Us. Retrieved August 4, 2020.

    Open source URL
  223. [223]
    Picus Sodinokibi January 2020

    Ozarslan, S. (2020, January 15). A Brief History of Sodinokibi. Retrieved August 5, 2020.

    Open source URL
  224. [224]
    Picus Sodinokibi January 2020

    Ozarslan, S. (2020, January 15). A Brief History of Sodinokibi. Retrieved August 5, 2020.

    Open source URL
  225. [225]
    Talos Sodinokibi April 2019

    Cadieux, P, et al (2019, April 30). Sodinokibi ransomware exploits WebLogic Server vulnerability. Retrieved August 4, 2020.

    Open source URL
  226. [226]
    Talos Sodinokibi April 2019

    Cadieux, P, et al (2019, April 30). Sodinokibi ransomware exploits WebLogic Server vulnerability. Retrieved August 4, 2020.

    Open source URL
  227. [227]
    BleepingComputer REvil 2021

    Abrams, L. (2021, March 19). REvil ransomware has a new ‘Windows Safe Mode’ encryption mode. Retrieved June 23, 2021.

    Open source URL
  228. [228]
    Cylance Sodinokibi July 2019

    Cylance. (2019, July 3). hreat Spotlight: Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  229. [229]
    Cylance Sodinokibi July 2019

    Cylance. (2019, July 3). hreat Spotlight: Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  230. [230]
    Group IB Ransomware May 2020

    Group IB. (2020, May). Ransomware Uncovered: Attackers’ Latest Methods. Retrieved August 5, 2020.

    Open source URL
  231. [231]
    Group IB Ransomware May 2020

    Group IB. (2020, May). Ransomware Uncovered: Attackers’ Latest Methods. Retrieved August 5, 2020.

    Open source URL
  232. [232]
    Intel 471 REvil March 2020

    Intel 471 Malware Intelligence team. (2020, March 31). REvil Ransomware-as-a-Service – An analysis of a ransomware affiliate operation. Retrieved August 4, 2020.

    Open source URL
  233. [233]
    Intel 471 REvil March 2020

    Intel 471 Malware Intelligence team. (2020, March 31). REvil Ransomware-as-a-Service – An analysis of a ransomware affiliate operation. Retrieved August 4, 2020.

    Open source URL
  234. [234]
    Kaspersky Sodin July 2019

    Mamedov, O, et al. (2019, July 3). Sodin ransomware exploits Windows vulnerability and processor architecture. Retrieved August 4, 2020.

    Open source URL
  235. [235]
    Kaspersky Sodin July 2019

    Mamedov, O, et al. (2019, July 3). Sodin ransomware exploits Windows vulnerability and processor architecture. Retrieved August 4, 2020.

    Open source URL
  236. [236]
    McAfee Sodinokibi October 2019

    McAfee. (2019, October 2). McAfee ATR Analyzes Sodinokibi aka REvil Ransomware-as-a-Service – What The Code Tells Us. Retrieved August 4, 2020.

    Open source URL
  237. [237]
    McAfee Sodinokibi October 2019

    McAfee. (2019, October 2). McAfee ATR Analyzes Sodinokibi aka REvil Ransomware-as-a-Service – What The Code Tells Us. Retrieved August 4, 2020.

    Open source URL
  238. [238]
    Secureworks GandCrab and REvil September 2019

    Secureworks . (2019, September 24). REvil: The GandCrab Connection. Retrieved August 4, 2020.

    Open source URL
  239. [239]
    Secureworks GandCrab and REvil September 2019

    Secureworks . (2019, September 24). REvil: The GandCrab Connection. Retrieved August 4, 2020.

    Open source URL
  240. [240]
    Secureworks REvil September 2019

    Counter Threat Unit Research Team. (2019, September 24). REvil/Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  241. [241]
    Secureworks REvil September 2019

    Counter Threat Unit Research Team. (2019, September 24). REvil/Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  242. [242]
    Kaspersky Sodin July 2019

    Mamedov, O, et al. (2019, July 3). Sodin ransomware exploits Windows vulnerability and processor architecture. Retrieved August 4, 2020.

    Open source URL
  243. [243]
    Kaspersky Sodin July 2019

    Mamedov, O, et al. (2019, July 3). Sodin ransomware exploits Windows vulnerability and processor architecture. Retrieved August 4, 2020.

    Open source URL
  244. [244]
    McAfee Sodinokibi October 2019

    McAfee. (2019, October 2). McAfee ATR Analyzes Sodinokibi aka REvil Ransomware-as-a-Service – What The Code Tells Us. Retrieved August 4, 2020.

    Open source URL
  245. [245]
    McAfee Sodinokibi October 2019

    McAfee. (2019, October 2). McAfee ATR Analyzes Sodinokibi aka REvil Ransomware-as-a-Service – What The Code Tells Us. Retrieved August 4, 2020.

    Open source URL
  246. [246]
    Cylance Sodinokibi July 2019

    Cylance. (2019, July 3). hreat Spotlight: Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  247. [247]
    Cylance Sodinokibi July 2019

    Cylance. (2019, July 3). hreat Spotlight: Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  248. [248]
    Intel 471 REvil March 2020

    Intel 471 Malware Intelligence team. (2020, March 31). REvil Ransomware-as-a-Service – An analysis of a ransomware affiliate operation. Retrieved August 4, 2020.

    Open source URL
  249. [249]
    Intel 471 REvil March 2020

    Intel 471 Malware Intelligence team. (2020, March 31). REvil Ransomware-as-a-Service – An analysis of a ransomware affiliate operation. Retrieved August 4, 2020.

    Open source URL
  250. [250]
    McAfee Sodinokibi October 2019

    McAfee. (2019, October 2). McAfee ATR Analyzes Sodinokibi aka REvil Ransomware-as-a-Service – What The Code Tells Us. Retrieved August 4, 2020.

    Open source URL
  251. [251]
    McAfee Sodinokibi October 2019

    McAfee. (2019, October 2). McAfee ATR Analyzes Sodinokibi aka REvil Ransomware-as-a-Service – What The Code Tells Us. Retrieved August 4, 2020.

    Open source URL
  252. [252]
    Secureworks GandCrab and REvil September 2019

    Secureworks . (2019, September 24). REvil: The GandCrab Connection. Retrieved August 4, 2020.

    Open source URL
  253. [253]
    Secureworks GandCrab and REvil September 2019

    Secureworks . (2019, September 24). REvil: The GandCrab Connection. Retrieved August 4, 2020.

    Open source URL
  254. [254]
    Secureworks REvil September 2019

    Counter Threat Unit Research Team. (2019, September 24). REvil/Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  255. [255]
    Secureworks REvil September 2019

    Counter Threat Unit Research Team. (2019, September 24). REvil/Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  256. [256]
    Secureworks GandCrab and REvil September 2019

    Secureworks . (2019, September 24). REvil: The GandCrab Connection. Retrieved August 4, 2020.

    Open source URL
  257. [257]
    Secureworks GandCrab and REvil September 2019

    Secureworks . (2019, September 24). REvil: The GandCrab Connection. Retrieved August 4, 2020.

    Open source URL
  258. [258]
    Secureworks REvil September 2019

    Counter Threat Unit Research Team. (2019, September 24). REvil/Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  259. [259]
    Secureworks REvil September 2019

    Counter Threat Unit Research Team. (2019, September 24). REvil/Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  260. [260]
    Kaspersky Sodin July 2019

    Mamedov, O, et al. (2019, July 3). Sodin ransomware exploits Windows vulnerability and processor architecture. Retrieved August 4, 2020.

    Open source URL
  261. [261]
    Kaspersky Sodin July 2019

    Mamedov, O, et al. (2019, July 3). Sodin ransomware exploits Windows vulnerability and processor architecture. Retrieved August 4, 2020.

    Open source URL
  262. [262]
    McAfee Sodinokibi October 2019

    McAfee. (2019, October 2). McAfee ATR Analyzes Sodinokibi aka REvil Ransomware-as-a-Service – What The Code Tells Us. Retrieved August 4, 2020.

    Open source URL
  263. [263]
    McAfee Sodinokibi October 2019

    McAfee. (2019, October 2). McAfee ATR Analyzes Sodinokibi aka REvil Ransomware-as-a-Service – What The Code Tells Us. Retrieved August 4, 2020.

    Open source URL
  264. [264]
    Secureworks REvil September 2019

    Counter Threat Unit Research Team. (2019, September 24). REvil/Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  265. [265]
    Secureworks REvil September 2019

    Counter Threat Unit Research Team. (2019, September 24). REvil/Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  266. [266]
    Intel 471 REvil March 2020

    Intel 471 Malware Intelligence team. (2020, March 31). REvil Ransomware-as-a-Service – An analysis of a ransomware affiliate operation. Retrieved August 4, 2020.

    Open source URL
  267. [267]
    Cylance Sodinokibi July 2019

    Cylance. (2019, July 3). hreat Spotlight: Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  268. [268]
    Intel 471 REvil March 2020

    Intel 471 Malware Intelligence team. (2020, March 31). REvil Ransomware-as-a-Service – An analysis of a ransomware affiliate operation. Retrieved August 4, 2020.

    Open source URL
  269. [269]
    Kaspersky Sodin July 2019

    Mamedov, O, et al. (2019, July 3). Sodin ransomware exploits Windows vulnerability and processor architecture. Retrieved August 4, 2020.

    Open source URL
  270. [270]
    McAfee Sodinokibi October 2019

    McAfee. (2019, October 2). McAfee ATR Analyzes Sodinokibi aka REvil Ransomware-as-a-Service – What The Code Tells Us. Retrieved August 4, 2020.

    Open source URL
  271. [271]
    Picus Sodinokibi January 2020

    Ozarslan, S. (2020, January 15). A Brief History of Sodinokibi. Retrieved August 5, 2020.

    Open source URL
  272. [272]
    Secureworks GandCrab and REvil September 2019

    Secureworks . (2019, September 24). REvil: The GandCrab Connection. Retrieved August 4, 2020.

    Open source URL
  273. [273]
    Secureworks REvil September 2019

    Counter Threat Unit Research Team. (2019, September 24). REvil/Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  274. [274]
    Talos Sodinokibi April 2019

    Cadieux, P, et al (2019, April 30). Sodinokibi ransomware exploits WebLogic Server vulnerability. Retrieved August 4, 2020.

    Open source URL
  275. [275]
    Tetra Defense Sodinokibi March 2020

    Tetra Defense. (2020, March). CAUSE AND EFFECT: SODINOKIBI RANSOMWARE ANALYSIS. Retrieved November 17, 2024.

    Open source URL
  276. [276]
    Cylance Sodinokibi July 2019

    Cylance. (2019, July 3). hreat Spotlight: Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  277. [277]
    Intel 471 REvil March 2020

    Intel 471 Malware Intelligence team. (2020, March 31). REvil Ransomware-as-a-Service – An analysis of a ransomware affiliate operation. Retrieved August 4, 2020.

    Open source URL
  278. [278]
    McAfee Sodinokibi October 2019

    McAfee. (2019, October 2). McAfee ATR Analyzes Sodinokibi aka REvil Ransomware-as-a-Service – What The Code Tells Us. Retrieved August 4, 2020.

    Open source URL
  279. [279]
    Secureworks GandCrab and REvil September 2019

    Secureworks . (2019, September 24). REvil: The GandCrab Connection. Retrieved August 4, 2020.

    Open source URL
  280. [280]
    Secureworks REvil September 2019

    Counter Threat Unit Research Team. (2019, September 24). REvil/Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.