All threat actors

A prolific ransomware-as-a-service operation, also known as Sodinokibi, active mainly from 2019 to 2021. Its affiliates conducted high-profile supply-chain and enterprise attacks, stole data, and encrypted systems for double extortion before international law-enforcement actions and arrests disrupted the group.

Also known as

Sodinokibi

Create a free account to see the reports

Sign in or create a free account to see every report that names REvil.

Create free account