2026 Gartner® Magic Quadrant™ 엔드포인트 보호 부문 Leader. 6년 연속 선정.6년 연속. Gartner® Magic Quadrant™ Leader 선정.더 알아보기
보안 침해가 발생했나요?블로그
시작하기문의하기
Header Navigation - KR
  • 플랫폼
    플랫폼 개요
    • Singularity Platform
      통합 엔터프라이즈 보안에 오신 것을 환영합니다
    • 보안을 위한 AI
      AI 기반 보안 솔루션의 선두주자
    • AI 보안
      보안이 강화된 AI 도구, 앱 및 에이전트로 AI 도입을 가속화하십시오.
    • 작동 방식
      Singularity XDR의 차이점
    • Singularity Marketplace
      원클릭 통합으로 XDR의 강력한 기능 활용하기
    • 가격 및 패키지
      한눈에 보는 비교 및 안내
    Data & AI
    • Purple AI
      제너레이티브 AI를 통한 보안 운영 가속화
    • Singularity Hyperautomation
      손쉬운 보안 프로세스 자동화
    • AI-SIEM
      자율 SOC를 위한 AI SIEM
    • AI Data Pipelines
      AI SIEM 및 데이터 최적화를 위한 보안 데이터 파이프라인
    • Singularity Data Lake
      데이터 레이크에 의해 통합된 AI 기반
    • Singularity Data Lake for Log Analytics
      온프레미스, 클라우드 또는 하이브리드 환경에서 원활하게 데이터 수집
    Endpoint Security
    • Singularity Endpoint
      자율 예방, 탐지 및 대응
    • Singularity XDR
      기본 및 개방형 보호, 탐지 및 대응
    • Singularity RemoteOps Forensics
      규모에 맞는 포렌식 오케스트레이션
    • Singularity Threat Intelligence
      포괄적인 적 인텔리전스
    • Singularity Vulnerability Management
      S1 에이전트 미설치 단말 확인
    • Singularity Identity
      신원 확인을 위한 위협 탐지 및 대응
    Cloud Security
    • Singularity Cloud Security
      AI 기반 CNAPP으로 공격 차단하기
    • Singularity Cloud Native Security
      클라우드 및 개발 리소스를 보호하려면
    • Singularity Cloud Workload Security
      실시간 클라우드 워크로드 보호 플랫폼
    • Singularity Cloud Data Security
      AI 기반 위협 탐지
    • Singularity Cloud Security Posture Management
      클라우드 구성 오류 감지 및 수정
    AI 보호
    • Prompt Security
      기업 전반에서 AI 도구 보호
  • SentinelOne을 선택해야 하는 이유
    SentinelOne을 선택해야 하는 이유
    • SentinelOne을 선택해야 하는 이유
      미래를 위해 개발된 사이버 보안
    • 고객사
      세계 최고 기업들의 신뢰
    • 업계 내 명성
      전문가를 통해 테스트 및 검증 완료
    • SentinelOne 소개
      자율적인 사이버 보안 부문의 선도업체
    SentinelOne 비교
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    업종
    • 에너지
    • 연방 정부
    • 금융
    • 보건 의료
    • 고등 교육
    • 초중등 교육
    • 제조
    • 소매
    • 주 및 지방 정부
  • 서비스
    관리형 서비스
    • 관리형 서비스 개요
      Wayfinder Threat Detection & Response
    • Threat Hunting
      세계적 수준의 전문성 및 위협 인텔리전스.
    • Managed Detection & Response
      전체 환경을 아우르는 24/7/365 전문 MDR.
    • Incident Readiness & Response
      DFIR, 침해 대응 준비 & 침해 평가.
    지원, 배포 및 상태 점검
    • 기술 계정 관리
      맞춤형 서비스를 통한 고객 성공
    • SentinelOne GO
      온보딩 가이드 및 배포 관련 자문
    • SentinelOne University
      실시간 및 주문형 교육
    • 서비스 개요
      끊김 없는 보안 운영을 위한 종합 솔루션
    • SentinelOne 커뮤니티
      커뮤니티 로그인
  • 파트너사
    SentinelOne 네트워크
    • MSSP 파트너
      SentinelOne으로 조기 성공 실현
    • Singularity Marketplace
      S1 기술력 확장
    • 사이버 위험 파트너
      전문가 대응 및 자문 팀에 협력 요청
    • 기술 제휴
      통합형 엔터프라이즈급 솔루션
    • SentinelOne for AWS
      전 세계 AWS 리전에서 호스팅
    • 채널 파트너
      협업을 통해 올바른 솔루션 제공
    • SentinelOne for Google Cloud
      통합되고 자율적인 보안으로 방어자에게 글로벌 규모의 우위를 제공합니다.
    프로그램 개요→
  • 리소스
    리소스 센터
    • 사례 연구
    • 데이터 시트
    • eBooks
    • 동영상
    • 웨비나
    • 백서
    • Events
    모든 리소스 보기→
    리소스 센터
    • 주요 기능
    • CISO/CIO용
    • 현장 스토리
    • ID
    • 클라우드
    • macOS
    • SentinelOne 블로그
    블로그→
    기술 리소스
    • SentinelLABS
    • 랜섬웨어 사례집
    • 사이버 보안 101
  • 회사 소개
    SentinelOne 소개
    • SentinelOne 소개
      사이버 보안 업계의 선도업체
    • SentinelLABS
      최신 위협 헌터를 위한 위협 연구
    • 채용
      최신 취업 기회
    • 보도 자료 및 뉴스
      회사 공지사항
    • 사이버 보안 블로그
      최신 사이버 보안 위협, 뉴스 등
    • FAQ
      자주 묻는 질문에 대한 답변 확인
    • 데이터 세트
      라이브 데이터 플랫폼
    • S 재단
      모두에게 더욱 안전한 미래 실현
    • S 벤처
      차세대 보안 및 데이터에 투자
시작하기문의하기
Back to Anthology
REvil
Published: November 30, 2022Last updated: September 17, 2025
RansomHubRhysida

REvil Ransomware: In-Depth Analysis, Detection, and Mitigation

As if ransomware itself wasn’t dangerous enough, a new type of attack involving ransomware is making waves in the cybersecurity community. Ransomware-as-a-Service (RaaS) operations are becoming more common and more profitable for threat actors looking to launch a variety of attacks. One such operation is known as REvil, and involved a core team of threat actors offering the malware to other attackers for a price.

Although the Russian Federal Security Service claims to have dismantled REvil and charged several of the ransomware group’s members, a deeper look at this type of ransomware and RaaS can help organizations protect themselves against these types of attacks in the future.

REvil Ransomware - Featured Image | SentinelOne

What Is REvil Ransomware?

REvil ransomware (also known as Sodinokibi) works like most other types of ransomware. It’s a file-blocking virus that typically encrypts data after infection and sends a ransom demand to the target with a time stamp. If the ransom isn’t paid in time, the ransom demand typically doubles. Since the attackers are the only ones with the decryption key, victims of REvil are usually at their mercy.

Additionally, REvil was one of the first types of ransomware to introduce double extortion, using stolen files to coerce its victims into paying the ransom by threatening to publish them online.

Although REvil was one of the most active ransomware variants in 2021, the Russian Federal Security Service purportedly shut it down following its attacks on critical infrastructure resulting in supply shortages and delays. However, organizations would be wise not to dismiss this type of ransomware. Instead, regrouping and restrategizing to prevent these types of attacks may be the best path forward.

What Is Ransomware as a Service?

REvil is one example of Ransomware-as-a-Service (RaaS), a relatively new business model involving ransomware groups selling or renting ransomware to affiliate threat actors. Today, the rise in RaaS is credited with being one of the primary reaons for the recent proliferation of ransomware attacks. In most cases, RaaS makes easier for a broad spectrum of threat actors to deploy ransomware against targets.

In the case of REvil, the ransomware group would reportedly demand a 40% cut of the ransom paid to the affiliates for providing access to the ransomware and any additional support. However, researchers supposedly discovered that the ransomware also contained a backdoor that allowed the core team to chat directly with victims and demand additional ransom payments, bypassing affiliates altogether.

REvil Ransomware History

REvil was first observed in early 2019 and continues to be one of the most formidable and contemporary ransomware threats in 2022. REvil has been instrumental in several high-profile, high-impact attacks including those against Kaseya and JBS.

What Does REvil Ransomware Target?

Revil ransomware commonly targets large enterprises, including government organizations, and educational institutions.  REvil is also known to heavily target healthcare, transportation, and technology industries as well.

REvil avoids targeting within the Commonwealth of Independent States.

How Does REvil Ransomware Work?

REvil typically spreads through the use of phishing emails, which contain a malicious attachment or link. When the victim clicks on the attachment or link, the ransomware is installed on their device. The other common method REvil Spread is utilizing vulnerable software.

Publicly known vulnerabilities used by REvil include:

  • CVE-2021-30116 – Kaseya
  • CVE-2021-30119 – Kaseya
  • CVE-2021-30110 – Kaseya
  • CVE-2019-19781 – Citrix
  • CVE-2019-11510 – Pulse Secure
  • CVE-2019-11539 – Pulse Secure
  • CVE-2018-13379 – Fortinet

REvil may also use other malware, such as trojans or backdoors, to gain access to the victim’s device, or to spread within the network. It could also exploit vulnerabilities in the victim’s system, or use other means, such as peer-to-peer networks, or drive-by downloads, to spread further.

REvil Ransomware Technical Details

REvil is associated with multiple actors  and threat families. At its core, REVil is a RaaS (Ransomware-as-a-Service) and is marketed to a very particular and exclusive clientele. Initial access and delivery are typically via publicly disclosed vulnerabilities (exploitation thereof) or via additional frameworks (e.g., Cobalt Strike, Trickbot).

REvil payloads are very aggressive and can very rapidly encrypt an entire drive and those adjacent and available. Recent variants have utilized Salsa20 for encryption due the optimal performance. In addition, recent updates have added the ability for REvil to encrypt systems while in safe mode, as well as improvements to the persistence mechanisms (e.g., Scheduled Tasks, Registry Run Key).

REvil will typically rely on WMI for system information discovery, and manipulation (e.g., terminating processes).

REvil maintains a public (TOR-based) blog where they list victims and any associated leakage or sale of data.

How to Detect REvil Ransomware

The SentinelOne Singularity XDR Platform detects and prevents malicious behaviors and artifacts associated with REvil.

In case you do not have SentinelOne deployed, detecting REvil ransomware requires a combination of technical and operational measures, which are designed to identify and flag suspicious activity on the network. This allows the organization to take appropriate action, and to prevent or mitigate the impact of the ransomware attack.

When trying to detect REvil without SentinelOne deployed, look for:

  1. Unexpected files or folders appearing on the victim’s device, with names such as “!.R5C”, “!.R5A”, or “!.R5E”.
  2. Files being encrypted with a strong encryption algorithm, such as AES-256.
  3. A ransom note appears on the victim’s device, which includes instructions on how to pay the ransom, and the deadline for payment.
  4. An increase in network traffic, as REvil communicates with the attacker’s command and control (C&C) server.
  5. Suspicious processes running on the victim’s device, such as “svchost.exe” or “csrss.exe”.
  6. An increase in error messages, or system crashes, as REvil infects the victim’s device.

Here more ways you can identify ransomware in your network:

Security Tools

Use anti-malware software or other security tools capable of detecting and blocking known ransomware variants. These tools may use signatures, heuristics, or machine learning algorithms, to identify and block suspicious files or activities.

Network Traffic

Monitor network traffic and look for indicators of compromise, such as unusual network traffic patterns or communication with known command-and-control servers.

Security Audits

Conduct regular security audits and assessments to identify network and system vulnerabilities and ensure that all security controls are in place and functioning properly.

Education & Training

Educate and train employees on cybersecurity best practices, including identifying and reporting suspicious emails or other threats.

Backup & Recovery Plan

Implement a robust backup and recovery plan to ensure that the organization has a copy of its data and can restore it in case of an attack.

How to Mitigate REvil Ransomware

The SentinelOne Singularity XDR Platform prevents REvil infections. The SentinelOne Singularity XDR Platform detects and prevents malicious behaviors and artifacts associated with REvil.

In case you do not have SentinelOne deployed, there are several steps your organizations can take:

Disconnect infected devices from the network

To prevent the ransomware from spreading and to isolate the threat, it is important to disconnect infected devices from the network as soon as possible. This can be done by unplugging the device, or by disabling the network adapter, or by disconnecting the device from the network through the network switch or router.

Run a malware scan

To remove REvil ransomware, it is recommended to run a malware scan on the infected device using anti-malware software, such as antimalware or anti-ransomware. This will identify and remove the ransomware, as well as any other malware that may be present on the device.

Restore from backups

To recover the encrypted files, it is recommended to restore from backups, if available. This can be done by restoring the files from a recent backup or by using a backup system, such as a backup server or a cloud backup service.

Consult with experts

If the ransomware cannot be removed, or if the encrypted files cannot be restored, it may be necessary to consult with security experts, such as forensic experts or incident response teams. These experts can help to assess the damage, to restore systems, and to prevent future attacks.

Purpose Built to Prevent Tomorrow’s Threats. Today.

Your most sensitive data lives on the endpoint and in the cloud. Protect what matters most from cyberattacks. Fortify every edge of the network with realtime autonomous protection.

Get a Demo

Frequently Asked Questions

REvil, also known as Sodinokibi, is a significant ransomware-as-a-service (RaaS) menace that emerged for the first time in April 2019. It encrypts the data in hacked systems and promises to restore them for payment of a ransom. REvil gained notoriety for conducting high-profile attacks and for employing double extortion tactics, threatening to publish stolen information if ransoms were not paid.

REvil is based on a RaaS model, where a central team creates the ransomware and employs affiliates to distribute it. The affiliates carry out the attacks with REvil’s malware, and the ransom money is split between the affiliates and REvil developers, promoting widespread distribution.

REvil has mainly targeted healthcare, finance, and legal services sectors. Its attacks have caused significant disruptions, especially in industries where data must be kept confidential, or users need it to be readily available.

REvil uses robust encryption algorithms, such as AES-256 encryption for encrypting files and RSA-2048 encryption for encrypting the encryption keys.

REvil operates across networks, exploiting software and systems vulnerabilities. It gains initial access with phishing emails and laterally propagates to exploit credentials. It is able to penetrate systems by exploiting Remote Desktop Protocol (RDP) connections.

Yes, REvil employs data exfiltration before encryption, a tactic known as double extortion. By stealing sensitive data and threatening release, REvil places extra pressure on victims to pay the ransom, both through data loss and possible reputational damage.

Organizations should implement multi-factor authentication and regularly update and patch systems to fix vulnerabilities. They can also protect against REvil by using tools like the SentinelOne Singularity XDR Platform.

Among the most significant attacks employing REvil ransomware are the July 2021 attack on Kaseya VSA, which affected multiple managed service providers and their clients and caused mass disruptions. Another considerable attack was directed against JBS S.A., a central meat processor, leading to severe operational disruptions.

Anthology Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the World’s Most Advanced Cybersecurity Platform

See how our intelligent, autonomous cybersecurity platform harnesses the power of data and AI to protect your organization now and into the future.

Request Demo
  • 시작하기
  • 데모 받기
  • 제품 둘러보기
  • SentinelOne을 선택해야 하는 이유
  • 가격 및 패키지
  • FAQ
  • 연락처
  • 문의
  • 지원
  • SentinelOne Status
  • 언어
  • 플랫폼
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • 서비스
  • Wayfinder TDR
  • SentinelOne GO
  • 기술 계정 관리
  • 지원 서비스
  • 업종
  • 에너지
  • 연방 정부
  • 금융
  • 보건 의료
  • 고등 교육
  • 초중등 교육
  • 제조
  • 소매소매
  • 주 및 지방 정부
  • Cybersecurity for SMB
  • 리소스
  • Blog
  • Labs
  • 사례 연구
  • 동영상
  • 제품 둘러보기
  • Events
  • Cybersecurity 101
  • eBooks
  • 웨비나
  • 백서
  • 언론
  • 뉴스
  • 랜섬웨어 사례집
  • 회사
  • 회사 소개
  • 고객사
  • 채용
  • 파트너사
  • 법무 및 규정 준수
  • 보안 및 규정 준수
  • S Foundation
  • S Ventures

©2026 SentinelOne, 판권 소유.

개인정보 고지 이용 약관

한국어