Revil Group Shutdown. Analyzing the Case

Revil Group Shutdown. Analyzing the Case

What’s happened to the REvil ransomware group?

On Saturday, October 17, the REvil group member (0_neday) started a topic on a Darknet forum. The exact forum is dedicated to cybersecurity, hacking and various other semi-legal things. He claimed that their domain server had been hijacked. Earlier, one of their main actors (under the nick “UNKNWN”) suddenly disappeared, and they thought he was dead, giving no attention to what happened. In September, after several months of the group inactivity, 0_neday introduced himself as a REvil member. He said that he backed REvil alive after several months of inactivity using the backups.

This person has likely ignored the rumors that the FBI did a great success in their investigation against the REvil group. To the moment when 0_neday decided to launch their network from the backups, the FBI have already compromised these backups. Hence, after the federals got an approval that they have really valid backups, they just did an interesting gesture – suddenly launched their own alteration of the landing page and blog of the REvil group. 0_neday says that he understood that their services were compromised after seeing this. However, he cannot find any leftovers in logs or something like that – hence, the third party who did this used a legit and normal access way (i.e. regular login into the system).

How could it happen?

Assuming all background information, a lot of cybersecurity experts supposed that UNKNWN disappearance is somehow related to the following events. This person could be captured by the FBI, and then he/she gave up all the credentials from REvil system. Nonetheless, REvil administrator (nickname “REvil”) ensures that all compromised elements of their system were deleted exactly after the UNKNWN have vanished.

What is the real matter of this incident? No one – even REvil administrators – don’t know. Possibly, the network compromise is the result of operator capturing, which happened at the edge of September 2021. Europol and Ukrainian Cyber Police, together with the FBI and several other executive authorities, captured the REvil ransomware operator. Possibly, he gave up information during the interrogation. This guy can barely be the disappeared UNKNWN, since he was conducting his activity up to the moment when police were at his door, while the aforementioned member was offline since June 2021.

Maya Lin-Takahashi
Author

Maya Lin-Takahashi

Maya is a hardware enthusiast who tests and reviews smart home devices, smartphones, wearables, and audio gear. She focuses on practical consumer value and build quality.