Ein Leader im Gartner® Magic Quadrant™ für Endpoint Protection Platforms 2025. Seit fünf Jahren in FolEin Leader im Gartner® Magic Quadrant™Bericht lesen
Erleben Sie eine Sicherheitsverletzung?Blog
Los geht'sKontakt
Header Navigation - DE
  • Plattform
    Plattform Übersicht
    • Singularity Platform
      Willkommen bei der integrierten Unternehmenssicherheit
    • KI für die Sicherheit
      Wegweisend bei KI-gestützten Sicherheitslösungen
    • Sicherung von KI
      Beschleunigen Sie die Einführung von KI mit sicheren KI-Tools, -Anwendungen und -Agenten.
    • Wie es funktioniert
      Der Singularity XDR Unterschied
    • Singularity Marketplace
      Ein-Klick-Integrationen, um die Leistungsfähigkeit von XDR zu erschließen
    • Preise & Pakete
      Vergleiche und Beratung im Überblick
    Data & AI
    • Purple AI
      Beschleunigen Sie SecOps mit generativer KI
    • Singularity Hyperautomation
      Einfaches Automatisieren von Sicherheitsprozessen
    • AI-SIEM
      Das KI-SIEM für das autonome SOC
    • AI Data Pipelines
      Sicherheitsdaten-Pipeline für KI-SIEM und Datenoptimierung
    • Singularity Data Lake
      Angetrieben durch KI, vereinheitlicht durch Data Lake
    • Singularity Data Lake for Log Analytics
      Nahtlose Aufnahme von Daten aus On-Premise-, Cloud- oder Hybrid-Umgebungen
    Endpoint Security
    • Singularity Endpoint
      Autonome Prävention, Erkennung und Reaktion
    • Singularity XDR
      Nativer und offener Schutz, Erkennung und Reaktion
    • Singularity RemoteOps Forensics
      Forensik im großen Maßstab orchestrieren
    • Singularity Threat Intelligence
      Umfassende Aufklärung des Gegners
    • Singularity Vulnerability Management
      Entdeckung von Rogue Assets
    • Singularity Identity
      Erkennung von und Reaktion auf Bedrohungen für Identitäten
    Cloud Security
    • Singularity Cloud Security
      Blockieren Sie Angriffe mit einer KI-gestützten CNAPP
    • Singularity Cloud Native Security
      Cloud und Entwicklungsressourcen sichern
    • Singularity Cloud Workload Security
      Plattform zum Schutz von Cloud-Workloads in Echtzeit
    • Singularity Cloud Data Security
      AI-gestützte Erkennung von Bedrohungen
    • Singularity Cloud Security Posture Management
      Erkennen und Beseitigen von Cloud-Fehlkonfigurationen
    Absicherung von KI
    • Prompt Security
      KI-Tools im gesamten Unternehmen absichern
  • Warum SentinelOne?
    Warum SentinelOne?
    • Warum SentinelOne?
      Cybersecurity, entwickelt für die Zukunft
    • Unsere Kunden
      Weltweit führende Unternehmen vertrauen auf uns
    • Branchen-Auszeichnungen
      Von Experten getestet
    • Über uns
      Der Branchenführer bei autonomer Cybersicherheit
    Vergleichen Sie SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Branchen
    • Energieversorger
    • Öffentlicher Sektor
    • Finanzsektor
    • Gesundheitswesen
    • Hochschulen
    • Fertigungsindustrie
    • Handel
    • Regionale & kommunale Verwaltung
  • Services
    Managed Services
    • Managed Services Übersicht
      Wayfinder Threat Detection & Response
    • Threat Hunting
      Erstklassige Expertise und Threat Intelligence.
    • Managed Detection & Response
      Rund-um-die-Uhr MDR-Experten für Ihre gesamte Umgebung.
    • Incident Readiness & Response
      DFIR, Vorbereitung auf Sicherheitsverletzungen & Kompromittierungsbewertungen.
    Support, Bereitstellung & Health Check
    • Technical Account Management
      Customer Success mit persönlichem Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live und On-Demand Training
    • Überblick zu unseren Services
      Umfassende Lösungen für reibungslose Sicherheitsoperationen
    • SentinelOne Community
      Community Login
  • Partner
    Unser Netzwerk
    • MSSP Partner
      Schnellerer Erfolg mit SentinelOne
    • Singularity Marketplace
      Erweitern Sie die Leistung der S1-Technologie
    • Cyber Risk Partner
      Einsatz von Pro-Response und Advisory Teams
    • Technologie-Partnerschaften
      Integrierte, unternehmensweite Lösungen
    • SentinelOne für AWS
      Gehostet in AWS-Regionen auf der ganzen Welt
    • Channel Partner
      Gemeinsam die richtigen Lösungen anbieten
    • SentinelOne for Google Cloud
      Vereinheitlichte, autonome Sicherheit, die Verteidigern einen Vorteil im globalen Maßstab verschafft.
    Programm-Übersicht→
  • Ressourcen
    Ressource-Center
    • Fallstudien
    • Datenblätter
    • eBooks
    • Reports
    • Videos
    • Webinars
    • White Papers
    • Events
    Alle Ressourcen anzeigen→
    Blog
    • Feature Spotlight
    • Für CISOs/CIOs
    • Von der Frontlinie
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Technische Ressourcen
    • SentinelLABS
    • Ransomware Anthologie
    • Cybersecurity 101
  • Unternehmen
    Über SentinelOne
    • Über SentinelOne
      Der Branchenführer im Bereich Cybersicherheit
    • SentinelLABS
      Threat Research für moderne Threat Hunter
    • Karriere
      Die aktuellen Jobangebote
    • Presse & News
      Bekanntmachungen der Firma
    • Cybersecurity Blog
      Die neuesten Cybersecurity-Bedrohungen, News, & mehr
    • FAQ
      Antworten auf die am häufigsten gestellten Fragen
    • DataSet
      Die Live Data Plattform
    • S Foundation
      Eine sicherere Zukunft für alle
    • S Ventures
      Wir investieren in die nächste Generation von Sicherheit und Daten
Los geht'sKontakt
Back to Anthology
REvil
Published: November 30, 2022Last updated: September 17, 2025
RansomHubRhysida

REvil Ransomware: In-Depth Analysis, Detection, and Mitigation

As if ransomware itself wasn’t dangerous enough, a new type of attack involving ransomware is making waves in the cybersecurity community. Ransomware-as-a-Service (RaaS) operations are becoming more common and more profitable for threat actors looking to launch a variety of attacks. One such operation is known as REvil, and involved a core team of threat actors offering the malware to other attackers for a price.

Although the Russian Federal Security Service claims to have dismantled REvil and charged several of the ransomware group’s members, a deeper look at this type of ransomware and RaaS can help organizations protect themselves against these types of attacks in the future.

REvil Ransomware - Featured Image | SentinelOne

What Is REvil Ransomware?

REvil ransomware (also known as Sodinokibi) works like most other types of ransomware. It’s a file-blocking virus that typically encrypts data after infection and sends a ransom demand to the target with a time stamp. If the ransom isn’t paid in time, the ransom demand typically doubles. Since the attackers are the only ones with the decryption key, victims of REvil are usually at their mercy.

Additionally, REvil was one of the first types of ransomware to introduce double extortion, using stolen files to coerce its victims into paying the ransom by threatening to publish them online.

Although REvil was one of the most active ransomware variants in 2021, the Russian Federal Security Service purportedly shut it down following its attacks on critical infrastructure resulting in supply shortages and delays. However, organizations would be wise not to dismiss this type of ransomware. Instead, regrouping and restrategizing to prevent these types of attacks may be the best path forward.

What Is Ransomware as a Service?

REvil is one example of Ransomware-as-a-Service (RaaS), a relatively new business model involving ransomware groups selling or renting ransomware to affiliate threat actors. Today, the rise in RaaS is credited with being one of the primary reaons for the recent proliferation of ransomware attacks. In most cases, RaaS makes easier for a broad spectrum of threat actors to deploy ransomware against targets.

In the case of REvil, the ransomware group would reportedly demand a 40% cut of the ransom paid to the affiliates for providing access to the ransomware and any additional support. However, researchers supposedly discovered that the ransomware also contained a backdoor that allowed the core team to chat directly with victims and demand additional ransom payments, bypassing affiliates altogether.

REvil Ransomware History

REvil was first observed in early 2019 and continues to be one of the most formidable and contemporary ransomware threats in 2022. REvil has been instrumental in several high-profile, high-impact attacks including those against Kaseya and JBS.

What Does REvil Ransomware Target?

Revil ransomware commonly targets large enterprises, including government organizations, and educational institutions.  REvil is also known to heavily target healthcare, transportation, and technology industries as well.

REvil avoids targeting within the Commonwealth of Independent States.

How Does REvil Ransomware Work?

REvil typically spreads through the use of phishing emails, which contain a malicious attachment or link. When the victim clicks on the attachment or link, the ransomware is installed on their device. The other common method REvil Spread is utilizing vulnerable software.

Publicly known vulnerabilities used by REvil include:

  • CVE-2021-30116 – Kaseya
  • CVE-2021-30119 – Kaseya
  • CVE-2021-30110 – Kaseya
  • CVE-2019-19781 – Citrix
  • CVE-2019-11510 – Pulse Secure
  • CVE-2019-11539 – Pulse Secure
  • CVE-2018-13379 – Fortinet

REvil may also use other malware, such as trojans or backdoors, to gain access to the victim’s device, or to spread within the network. It could also exploit vulnerabilities in the victim’s system, or use other means, such as peer-to-peer networks, or drive-by downloads, to spread further.

REvil Ransomware Technical Details

REvil is associated with multiple actors  and threat families. At its core, REVil is a RaaS (Ransomware-as-a-Service) and is marketed to a very particular and exclusive clientele. Initial access and delivery are typically via publicly disclosed vulnerabilities (exploitation thereof) or via additional frameworks (e.g., Cobalt Strike, Trickbot).

REvil payloads are very aggressive and can very rapidly encrypt an entire drive and those adjacent and available. Recent variants have utilized Salsa20 for encryption due the optimal performance. In addition, recent updates have added the ability for REvil to encrypt systems while in safe mode, as well as improvements to the persistence mechanisms (e.g., Scheduled Tasks, Registry Run Key).

REvil will typically rely on WMI for system information discovery, and manipulation (e.g., terminating processes).

REvil maintains a public (TOR-based) blog where they list victims and any associated leakage or sale of data.

How to Detect REvil Ransomware

The SentinelOne Singularity XDR Platform detects and prevents malicious behaviors and artifacts associated with REvil.

In case you do not have SentinelOne deployed, detecting REvil ransomware requires a combination of technical and operational measures, which are designed to identify and flag suspicious activity on the network. This allows the organization to take appropriate action, and to prevent or mitigate the impact of the ransomware attack.

When trying to detect REvil without SentinelOne deployed, look for:

  1. Unexpected files or folders appearing on the victim’s device, with names such as “!.R5C”, “!.R5A”, or “!.R5E”.
  2. Files being encrypted with a strong encryption algorithm, such as AES-256.
  3. A ransom note appears on the victim’s device, which includes instructions on how to pay the ransom, and the deadline for payment.
  4. An increase in network traffic, as REvil communicates with the attacker’s command and control (C&C) server.
  5. Suspicious processes running on the victim’s device, such as “svchost.exe” or “csrss.exe”.
  6. An increase in error messages, or system crashes, as REvil infects the victim’s device.

Here more ways you can identify ransomware in your network:

Security Tools

Use anti-malware software or other security tools capable of detecting and blocking known ransomware variants. These tools may use signatures, heuristics, or machine learning algorithms, to identify and block suspicious files or activities.

Network Traffic

Monitor network traffic and look for indicators of compromise, such as unusual network traffic patterns or communication with known command-and-control servers.

Security Audits

Conduct regular security audits and assessments to identify network and system vulnerabilities and ensure that all security controls are in place and functioning properly.

Education & Training

Educate and train employees on cybersecurity best practices, including identifying and reporting suspicious emails or other threats.

Backup & Recovery Plan

Implement a robust backup and recovery plan to ensure that the organization has a copy of its data and can restore it in case of an attack.

How to Mitigate REvil Ransomware

The SentinelOne Singularity XDR Platform prevents REvil infections. The SentinelOne Singularity XDR Platform detects and prevents malicious behaviors and artifacts associated with REvil.

In case you do not have SentinelOne deployed, there are several steps your organizations can take:

Disconnect infected devices from the network

To prevent the ransomware from spreading and to isolate the threat, it is important to disconnect infected devices from the network as soon as possible. This can be done by unplugging the device, or by disabling the network adapter, or by disconnecting the device from the network through the network switch or router.

Run a malware scan

To remove REvil ransomware, it is recommended to run a malware scan on the infected device using anti-malware software, such as antimalware or anti-ransomware. This will identify and remove the ransomware, as well as any other malware that may be present on the device.

Restore from backups

To recover the encrypted files, it is recommended to restore from backups, if available. This can be done by restoring the files from a recent backup or by using a backup system, such as a backup server or a cloud backup service.

Consult with experts

If the ransomware cannot be removed, or if the encrypted files cannot be restored, it may be necessary to consult with security experts, such as forensic experts or incident response teams. These experts can help to assess the damage, to restore systems, and to prevent future attacks.

Purpose Built to Prevent Tomorrow’s Threats. Today.

Your most sensitive data lives on the endpoint and in the cloud. Protect what matters most from cyberattacks. Fortify every edge of the network with realtime autonomous protection.

Get a Demo

Frequently Asked Questions

REvil, also known as Sodinokibi, is a significant ransomware-as-a-service (RaaS) menace that emerged for the first time in April 2019. It encrypts the data in hacked systems and promises to restore them for payment of a ransom. REvil gained notoriety for conducting high-profile attacks and for employing double extortion tactics, threatening to publish stolen information if ransoms were not paid.

REvil is based on a RaaS model, where a central team creates the ransomware and employs affiliates to distribute it. The affiliates carry out the attacks with REvil’s malware, and the ransom money is split between the affiliates and REvil developers, promoting widespread distribution.

REvil has mainly targeted healthcare, finance, and legal services sectors. Its attacks have caused significant disruptions, especially in industries where data must be kept confidential, or users need it to be readily available.

REvil uses robust encryption algorithms, such as AES-256 encryption for encrypting files and RSA-2048 encryption for encrypting the encryption keys.

REvil operates across networks, exploiting software and systems vulnerabilities. It gains initial access with phishing emails and laterally propagates to exploit credentials. It is able to penetrate systems by exploiting Remote Desktop Protocol (RDP) connections.

Yes, REvil employs data exfiltration before encryption, a tactic known as double extortion. By stealing sensitive data and threatening release, REvil places extra pressure on victims to pay the ransom, both through data loss and possible reputational damage.

Organizations should implement multi-factor authentication and regularly update and patch systems to fix vulnerabilities. They can also protect against REvil by using tools like the SentinelOne Singularity XDR Platform.

Among the most significant attacks employing REvil ransomware are the July 2021 attack on Kaseya VSA, which affected multiple managed service providers and their clients and caused mass disruptions. Another considerable attack was directed against JBS S.A., a central meat processor, leading to severe operational disruptions.

Anthology Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the World’s Most Advanced Cybersecurity Platform

See how our intelligent, autonomous cybersecurity platform harnesses the power of data and AI to protect your organization now and into the future.

Request Demo
  • Fangen Sie an!
  • Demo anforden
  • Produkt-Tour
  • Warum SentinelOne
  • Preise & Pakete
  • FAQ
  • Kontakt
  • Kontaktieren Sie uns
  • Support
  • SentinelOne Status
  • Sprache
  • Plattform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support-Services
  • Branchen
  • Energieversorger
  • Öffentlicher Sektor
  • Finanzsektor
  • Gesundheitswesen
  • Hochschulen
  • Fertigungsindustrie
  • Retail
  • Regionale & kommunale Verwaltung
  • Cybersecurity for SMB
  • Ressourcen
  • Blog
  • Labs
  • Fallstudien
  • Videos
  • Produkt-Tour
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • White Papers
  • Presse
  • News
  • Ransomware Anthologie
  • Unternehmen
  • Über uns
  • Unsere Kunden
  • Karriere
  • Partner
  • Legal & Compliance
  • Security & Compliance
  • S Foundation
  • S Ventures

©2026 SentinelOne, Alle Rechte vorbehalten.

Hinweis zum Datenschutz Nutzungsbedingungen

Deutsch