REvil ransomware gang taken offline by multinational effort

An abstract image of padlocks overlaying a digital background.
(Image credit: Shutterstock)

In a welcome move, sources have confirmed that the recent troubles plaguing the notorious REvil ransomware operator are the result of a concerted effort by various cybersecurity agencies.

Reuters credits REvil’s latest disappearance to the US based on insights shared by three private sector cyber experts working with US security agencies and one former official.

VMware’s head of cybersecurity strategy Tom Kellermann, an advisor to the US Secret Service on cybercrime investigations, noted that REvil was a high priority target for the law enforcement and intelligence agencies.

TechRadar needs you!

We're looking at how our readers use VPNs with streaming sites like Netflix so we can improve our content and offer better advice. This survey won't take more than 60 seconds of your time, and we'd hugely appreciate if you'd share your experiences with us.

>> Click here to start the survey in a new window <<

"The FBI, in conjunction with Cyber Command, the Secret Service and like-minded countries, have truly engaged in significant disruptive actions against these groups,” Kellermann told Reuters.

Done and dusted

Earlier this week, REvil’s was forced to take down its online infrastructure, hosted on the dark web, in response to an unidentified party hijacking the gang’s domains.

The news of the hijack was shared by the gang’s official representative known as "0_neday," who reportedly was instrumental in restarting the group's operations after a similar shutdown earlier this year.

"The server was compromised, and they were looking for me," 0_neday wrote on a cybercrime forum.

REvil has been behind some of the most extravagant ransomware operations of late including the one against managed service providers (MSP) by exploiting a vulnerability in the Kaseya VSA remote management software to infect thousands of computers around the world.

Action against Russia-based threat actors, including REvil, featured prominently in the US-Russian Presidential talks in Geneva earlier this year.

US President Joe Biden has assured that cybersecurity is one of the top priorities for his administration. While his administration has announced several steps and measures to strengthen the cybersecurity posture, REvil’s take down is perhaps one of the boldest displays of its intent in its fight against ransomware.

Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
Ransomware
8base ransomware site taken down in global police operation
Cryptocurrencies
Ransomware’s favorite Russian crypto exchange seized by law enforcement
US President Donald Trump speaks to the press as he signs an executive order to create a US sovereign wealth fund, in the Oval Office of the White House on February 3, 2025, in Washington, DC.
US set to pause cyber-offensive operations against Russia - but CISA says it won't stop
data recovery
Ghost ransomware has hit firms in over 70 countries, FBI and CISA warn
A laptop with a red screen with a white skull on it with the message: &quot;RANSOMWARE. All your files are encrypted.&quot;
Less than half of ransomware incidents end in payment - but you should still be on your guard
ransomware avast
“Every organization is vulnerable” - ransomware dominates security threats in 2024, so how can your business stay safe?
Latest in Security
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Coinbase targeted after recent Github attacks
hacker.jpeg
Key trusted Microsoft platform exploited to enable malware, experts warn
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Latest in News
Zendesk Relate 2025
Zendesk Relate 2025 - everything you need to know as the event unfolds
Disney Plus logo with popcorn
You can finally tell Disney+ to stop bugging you about that terrible Marvel show you regret starting
Google Gemini AI
Gemini can now see your screen and judge your tabs
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Philips Hue
Philips Hue might be working on a video doorbell, and according to a new report, we just got our first look at it
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand