REvil

S0496

Malware.View on attack.mitre.org

About this malware

REvil is a ransomware family that has been linked to the GOLD SOUTHFIELD group and operated as ransomware-as-a-service (RaaS) since at least April 2019. REvil, which as been used against organizations in the manufacturing, transportation, and electric sectors, is highly configurable and shares code similarities with the GandCrab RaaS.

Techniques used35

Procedure examples35

TechniqueProcedure example
T1007
System Service Discovery

REvil can enumerate active services.

T1012
Query Registry

REvil can query the Registry to get random file extensions to append to encrypted files.

T1027.011
Fileless Storage

REvil can save encryption parameters and system information in the Registry.

T1027.013
Encrypted/Encoded File

REvil has used encrypted strings and configuration files.

T1036.005
Match Legitimate Resource Name or Location

REvil can mimic the names of known executables.

T1041
Exfiltration Over C2 Channel

REvil can exfiltrate host and malware information to C2 servers.

T1047
Windows Management Instrumentation

REvil can use WMI to monitor for and kill specific processes listed in its configuration file.

T1055
Process Injection

REvil can inject itself into running processes on a compromised host.

T1059.001
PowerShell

REvil has used PowerShell to delete volume shadow copies and download files.

T1059.003
Windows Command Shell

REvil can use the Windows command line to delete volume shadow copies and disable recovery.

T1059.005
Visual Basic

REvil has used obfuscated VBA macros for execution.

T1069.002
Domain Groups

REvil can identify the domain membership of a compromised host.

T1070.004
File Deletion

REvil can mark its binary code for deletion after reboot.

T1071.001
Web Protocols

REvil has used HTTP and HTTPS in communication with C2.

T1082
System Information Discovery

REvil can identify the username, machine name, system language, keyboard layout, and OS version on a compromised host.

View all 35 procedure examples

Groups that use it2

Campaigns0

None recorded.

References3

  1. Group IB Ransomware May 2020 Open source
    Group IB. (2020, May). Ransomware Uncovered: Attackers’ Latest Methods. Retrieved August 5, 2020.
  2. Intel 471 REvil March 2020 Open source
    Intel 471 Malware Intelligence team. (2020, March 31). REvil Ransomware-as-a-Service – An analysis of a ransomware affiliate operation. Retrieved August 4, 2020.
  3. Secureworks REvil September 2019 Open source
    Counter Threat Unit Research Team. (2019, September 24). REvil/Sodinokibi Ransomware. Retrieved August 4, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.