Remove revils-tor-sites-are-back-with-new-ransomware
article thumbnail

REvil’s TOR Sites Are Back With New Ransomware

Heimadal Security

Discovered in April 2019, the REvil/Sodinokibi ransomware (AKA Sodin) is a highly evasive ransomware that encrypts files and deletes the ransom request message after infection. REvil is a perfect […]. The post REvil’s TOR Sites Are Back With New Ransomware appeared first on Heimdal Security Blog.

article thumbnail

It’s business as usual for REvil ransomware

Malwarebytes

After the FBS arrested 14 of its members in January, and a subsequent lull in action, the REvil ransomware gang appears to be back. To the trained eye, REvil’s movements seem out of sorts. The sites the nodes point to looked nothing like REvil’s. REvil ransomware: a brief look back.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

A Closer Look at the Snatch Data Ransom Group

Krebs on Security

Earlier this week, KrebsOnSecurity revealed that the darknet website for the Snatch ransomware group was leaking data about its users and the crime gang’s internal operations. It continues: “Prior to deploying the ransomware, Snatch threat actors were observed spending up to three months on a victim’s system.

article thumbnail

Bitdefender released free REvil ransomware decryptor that works for past victims

Security Affairs

Researchers from Bitdefender released a free master decryptor for the REvil ransomware operation that allows past victims to recover their files for free. On July 2, the REvil gang hit the Kaseya cloud-based MSP platform impacting MSPs and their customers. The Tor leak site, the payment website “decoder[.]re”,

article thumbnail

REvil ransomware disappears after Tor services hijacked

Malwarebytes

The REvil ransomware group has shut down their operation for the second time this year after losing control over their Tor-based domains. REvil’s first shutdown was in July 2021, after the gang successfully pulled off a supply chain attack against Managed Service Provider Kaseya. This is one of them. The comeback.

article thumbnail

REvil Ransomware Group: The Sequel

SecureWorld News

The infamous REvil ransomware gang, also known as Sodinokibi, appears to be making a comeback after months of hiatus. A new ransomware strain has been discovered by Jakub Kroustek, the Malware Research Director at Avast, suggesting the malicious cyber group has resumed attacking organizations. September 9, 2021.

article thumbnail

The story of the year: ransomware in the headlines

SecureList

In the past twelve months, the word “ransomware” has popped up in countless headlines worldwide across both print and digital publications: The Wall Street Journal , the BBC , the New York Times. Words like Babuk and REvil have entered the everyday lexicon. began adopting the new approach. ” in 2021.