REvil / Sodinokibi
View MITRE Group Page ↗Key Facts
- Attributed Country: Russian Federation.
- ATT&CK Group Reference: G0115 (REvil / Sodinokibi).
- Linked to 2 primary court prosecution records.
- Identified 2 individually charged operatives.
Primary ATT&CK Techniques Employed
| Technique | Frequency |
|---|---|
| T1190 Exploit Public-Facing Application | 1 incidents |
| T1574.002 DLL Side-Loading | 1 incidents |
| T1486 Data Encrypted for Impact | 1 incidents |
| T1569.002 Service Execution | 1 incidents |
| T1082 System Information Discovery | 1 incidents |
Prosecution Cases Attributed to This Actor
U.S. v. Yaroslav Vasinskyi (Kaseya VSA / REvil Ransomware)
Ukrainian national and REvil ransomware affiliate responsible for deploying the ransomware attack that hijacked Kaseya VSA management software, instantly encrypting up to 1,500 downstream businesses on July 4th weekend.
U.S. v. Aleksandr Sikerin & Yevgeniy Polyanin (REvil Operations)
International enforcement action against REvil ransomware money exchangers and operators, recovering $6.1 million in ransomware proceeds extorted from businesses and local governments across the United States.
Targeted Defensive Hardening for REvil / Sodinokibi
Primary Initial Access Defense
Enforce hardware FIDO2 multi-factor authentication across all perimeter VPN, Citrix, and cloud data portals. Prohibit SMS or push-based MFA that can be bypassed via vishing or SIM swapping.
Lateral Movement Interception
Restrict internal SMB (port 445) and RPC traversal between workstation subnets. Implement tiered Active Directory administration so domain administrator credentials are never cached on endpoints.