Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ransomware-group-operationenforcement-actioncybercrime-service-ecosystemthreat-infrastructure-tracking

Operation GoldDust Arrests REvil Affiliates and Disrupts Ransomware Network

Updated 28d agoFirst seen May 25, 20263 sources

Romanian authorities arrested two suspected Sodinokibi/REvil affiliates as part of Operation GoldDust, a multinational law-enforcement campaign targeting operators tied to both REvil and GandCrab. Europol said the suspects were linked to roughly 5,000 infections and about €500,000 in ransom payments, while the broader group of arrested affiliates was suspected of around 7,000 infections and demands exceeding €200 million. Since February 2021, authorities in 17 countries, working with Europol, Eurojust, and INTERPOL, had arrested seven suspects connected to the two ransomware families, including a REvil affiliate associated with the Kaseya supply-chain attack and other suspects detained in South Korea and Kuwait.

The arrests followed wider pressure on REvil’s ransomware-as-a-service operation after its infrastructure was disrupted and its public-facing sites went offline. Reporting indicated the gang shut down after U.S. Cyber Command hijacked one of its sites and the operators realized they had been compromised, adding to the strain from coordinated international investigations. Europol said private-sector partners including Bitdefender, KPN, and McAfee Enterprise supported the operation with technical analysis and decryptors distributed through No More Ransom, enabling more than 50,000 decryptions, helping over 1,400 companies recover from REvil infections, and preventing losses worth hundreds of millions of euros.

Share:
Operation GoldDust Arrests REvil Affiliates and Disrupts Ransomware Network
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Nov 8, 20215y ago

Europol announces Operation GoldDust results against REvil affiliates

On 2021-11-08, Europol publicly announced that five affiliates to Sodinokibi/REvil had been 'unplugged' through Operation GoldDust. The agency said the arrested affiliates were suspected of around 7,000 infections and had demanded more than €200 million in ransom.

Authorities arrest REvil affiliate tied to the Kaseya attack

During the 2021 Operation GoldDust effort, law enforcement arrested a REvil affiliate connected to the Kaseya supply-chain ransomware attack. Europol cited this as one of the notable arrests made before November 2021.

Nov 4, 20215y ago

Romanian authorities arrest two suspected REvil affiliates

On 2021-11-04, Romanian authorities arrested two suspects accused of cyber-attacks involving Sodinokibi/REvil. Europol said the pair were allegedly responsible for about 5,000 infections and roughly €500,000 in ransom payments.

Additional REvil/GandCrab affiliates arrested in South Korea and Kuwait

Before November 2021, authorities also arrested multiple ransomware affiliates in South Korea and Kuwait as part of the broader multinational crackdown. Europol said these arrests contributed to a total of seven suspects detained since February 2021.

Nov 3, 20215y ago

Cyber Command hijacks REvil infrastructure, contributing to gang shutdown

The Washington Post reported that U.S. Cyber Command hijacked a REvil site, and the gang subsequently shut down after realizing it had itself been compromised. This marked a major disruption of the ransomware group's operations.

Operation GoldDust begins targeting REvil and GandCrab affiliates

By February 2021, international law enforcement under Operation GoldDust had begun coordinated action against affiliates of the REvil and GandCrab ransomware operations. Europol said arrests linked to the two ransomware families started from this period onward.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.