revil
Sodinokibi ransomware group also known as REvil (Ransomware Evil) operates as a ransomware-as-a-service (RaaS) model. After the group compromised his victims, they would threaten to publish the victim's sensitive data on their darknet blog named 'Happy Blog', unless the ransom is paid. The ransomware malware code used by REvil is pretty similar to the ransomware code used by DarkSide - a different threat actor. REvil group claims to steal information after a successful attack on the supplier of the tech giant Apple and stole confidential schematics of their upcoming products.
Niveau de menace
MOYEN
Tactiques, techniques et procédures (TTP)
DiscoveryEnum
- AdFind
- Bloodhound
Exfiltration
- PrivatLab
- RClone
- Sendspace
LOLBAS
- BITSAdmin
Offsec
- Cobalt Strike
Vérifier si vous êtes touché
Cherchez dans notre base si votre organisation figure sur la liste des victimes de revil.
score de risque · catégories de menace · sources · ancienneté · confiance — en une requête