REvil
MITRE G0106Also known as REvil/Sodinokibi RaaS Affiliate, Sodinokibi
Reports
8
First seen
Jul 3, 2021
Last seen
Jul 17, 2026
Motivation
Financial
Relationships
Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.
Targeting
Sectors
Victim regions
×1×2
United States×2
Germany×1
Victim country, only when stated. Corpus is predominantly English-language reporting, so US/EU coverage is overweighted relative to true victim distribution.
Top ATT&CK techniques
T1190 Exploit Public-Facing Application ×9T1486 Data Encrypted for Impact ×7T1078 Valid Accounts ×3T1195 Supply Chain Compromise ×3T1562.001 Impair Defenses: Disable or Modify Tools ×2T1047 Windows Management Instrumentation ×2T1036 Masquerading ×1T1021.001 Remote Services: Remote Desktop Protocol ×1T1566 Phishing ×1T1218 System Binary Proxy Execution ×1T1657 Financial Theft ×1T1567 Exfiltration Over Web Service ×1
Indicators
filename ×16hash_md5 ×4ip_v4 ×4registry_key ×3email ×3hash_sha256 ×3url ×2cve ×2
Indicator values are available on Pro and via the API.
Associated CVEs
Recent reports
High