REvil returns, but under another name

cybercriminal
(Image credit: Pixabay)

The emergence of a new threat actor in underground forums has led cybersecurity experts to speculate the outfit could perhaps just be REvil ransomware operator under a changed name.

Earlier this month, the notorious Russia-based ransomware group took all its online properties offline, leading to speculation that the group could have been hit by law enforcement agencies, following its extravagant attack against managed service providers (MSP) by exploiting a vulnerability in the Kaseya VSA remote management software to infect thousands of computers around the world.

Identifying themselves as BlackMatter, the new threat actor has expressed interest in purchasing access to compromised corporate networks in the US, UK, Canada, and Australia.

TechRadar needs you!

We're looking at how our readers use VPNs with streaming sites like Netflix so we can improve our content and offer better advice. This survey won't take more than 60 seconds of your time, and we'd hugely appreciate if you'd share your experiences with us.

>> Click here to start the survey in a new window <<

Analysts at risk intelligence firm Flashpoint have drawn several similarities between BlackMatter and REvil regarding their tactics and policy of staying clear of medical and government institutions.

No smoking gun

After registering on the Russian-language hacker forums, XSS and Exploit, BlackMatter made a substantial deposit of four bitcoin (about $150,000) in an escrow account, before posting its request looking for targets.

The seriousness of BlackMatter’s intent is what brought the group immediately to the attention of observers.

However, the Flashpoint researchers note that the new group could just be copycats imitating REvil’s behavior to gain immediate credibility as its reincarnation. 

Furthermore, while the language of their post, and their goals clearly point to the fact that BlackMatter is a ransomware operator, the researchers suggest that one shouldn’t jump to conclusion just yet since “two posts and a large escrow account do not make a ransomware group.”

Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
ransomware avast
“Every organization is vulnerable” - ransomware dominates security threats in 2024, so how can your business stay safe?
A digital representation of a lock
Exploits on the rise: How defenders can combat sophisticated threat actors
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
Ransomware
Fortinet firewall bugs are being targeted by LockBit ransomware hackers
An image of network security icons for a network encircling a digital blue earth.
Why effective cybersecurity is a team effort
A person at a laptop with a cybersecure lock symbol floating above it.
Cybercrime gang targets victims with "triple threat" attacks
Latest in Security
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Latest in News
Millwall FC The Den
The UK's first football club mobile network is here - but you probably won't guess which team has launched it
The Witcher 4
You're probably not playing The Witcher 4 until 2027 at the earliest, per CD Projekt's latest financial update
Apple iPhone 16 Pro REVIEW
The iPhone 17 Air looks impressively slim in this new comparison image, but that just makes me more worried about the specs
Matt Murdock smiling in Daredevil: Born Again episode 5 and Kamala Khan looking stunned in The Marvels
Daredevil: Born Again episode 5 just revealed what Kamala Khan has been up to since The Marvels, and now I'm more excited for the next superhero team to appear in the MCU
Google Pixel Watch 3, 41mm and 45mm
Google says it will fix broken Wear OS 5.1 update, but why does this keep happening?
DeepSeek
DeepSeek’s new AI is smarter, faster, cheaper, and a real rival to OpenAI's models