Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ransomware-group-operationenforcement-actioncybercrime-service-ecosystemthreat-infrastructure-tracking

REvil Arrests Disrupted the Gang but Failed to Stop Its Reemergence

Updated 28d agoFirst seen May 25, 20266 sources

Law enforcement action against REvil dismantled key parts of one of the most prolific cybercriminal operations, leading to arrests tied to the ransomware gang’s infrastructure and operators. The takedown marked a significant blow against a group long associated with high-impact extortion campaigns, affiliate-driven ransomware activity, and attacks that disrupted organizations across multiple sectors.

Despite those arrests, REvil’s reemergence showed how resilient major ransomware ecosystems remain after headline enforcement actions. The group’s return underscored the persistence of its criminal model, in which branding, tooling, and affiliate relationships can survive leadership disruption, allowing extortion operations to resume even after authorities seize infrastructure and detain suspected members.

Share:
REvil Arrests Disrupted the Gang but Failed to Stop Its Reemergence
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Sep 29, 20224y ago

Trellix publishes analysis of REvil arrests and reemergence

Trellix published a blog post titled "Dismantling a Prolific Cybercriminal Empire: REvil Arrests and Reemergence," indicating analysis of the REvil cybercriminal group's arrests and subsequent return. No further event details are provided in the reference content.

Oct 25, 20215y ago

REvil disruption impacts its ransomware-as-a-service operation

By 2021-10-25, reporting described REvil as disrupted, with consequences for its ransomware-as-a-service model and broader affiliate ecosystem. This reflects a distinct development in the group's operational status preceding later analysis of arrests and reemergence.

REvil Ransomware Disrupted: Impact on RaaS &...
Oct 19, 20215y ago

REvil members claim shutdown after infrastructure takeover

On 2021-10-19, messages attributed to REvil operator '0_neday' said the group was ending operations after losing control of its infrastructure and amid internal conflict. Reporting said someone had taken over REvil's Tor payment portal and leak site, possibly using keys belonging to the missing spokesperson 'Unknown'.

Revil tire (encore) sa révérence - ZDNET
Oct 18, 20215y ago

REvil ransomware operation shuts down again

Security reporting said the REvil ransomware operation went offline again, marking a renewed disruption to the group's infrastructure and activity. This shutdown predates later reporting that described broader impacts on its ransomware-as-a-service operation.

REvil ransomware operation shuts down once again
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

REvil Arrests Disrupted the Gang but Failed to Stop Its Reemergence | Mallory