REvil ransomware is officially back, experts claim

Representational image depecting cybersecurity protection
(Image credit: Shutterstock)

Fresh evidencehas emerged that the notorious REvil ransomware is back with a vengeance, as newly discovered samples point to the fact that the group is now indiscriminate in the choice of its targets.

Cybersecurity researchers from Secureworks analyzed new malware samples recently uploaded to VirusTotal and came to the conclusion that whoever was behind it probably had access to REvil’s source code in the past. 

That led the researchers to believe that this is probably the same group whose operations were shut down late in 2021.

Share your thoughts on Cybersecurity and get a free copy of the Hacker's Manual 2022end of this survey

Share your thoughts on Cybersecurity and get a free copy of the Hacker's Manual 2022. Help us find how businesses are preparing for the post-Covid world and the implications of these activities on their cybersecurity plans. Enter your email at the end of this survey to get the bookazine, worth $10.99/£10.99.

Nothing is off limits any more

"The identification of multiple samples containing different modifications and the lack of an official new version indicate that REvil is under active development," the researchers said in a blog post announcing the news.

A new REvil leak site was recently sprung up. This newest sample, as well as an older sample, discovered in October last year, all point to REvil being active again.

In these new versions, researchers spotted upgrades in the string decryption logic, making it rely on a new command-line argument. Hard-coded public keys have been updated, as well as configuration storage location and the data format for affiliate tracking.

But perhaps the biggest change is the removal of off-limits regions. Older versions of REvil would check the geographical location of the infected endpoint, and if it met certain criteria (for example, if it was in a Russian-speaking community), would not activate. 

This is no longer the case.

"The October 2021 REvil sample removed code that verified the ransomware was not executing on a system that resided within a prohibited region," the CTU researchers wrote. "This removal enabled REvil to execute on any system regardless of its location."

REvil was initially shut down after a joint US-Russia operation, with the Russians arresting more than a dozen members. 

As Russia’s invasion of Ukraine soured relations between it and the US, the US government went ahead and unilaterally shut down the communication channel it had on cybersecurity with Moscow. As a result, the US has also withdrawn itself from the negotiation process regarding REvil.

Prior to Secureworks’ analysis, other cybersecurity firms warned of REvil’s resurgence, including Avast, Advanced Intel, R3MRUM, and others.

Via: The Register

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
More reports claim 2024 was the worst year for ransomware attacks yet
ransomware avast
“Every organization is vulnerable” - ransomware dominates security threats in 2024, so how can your business stay safe?
Russia
Major Russian hacking group shifts focus to US and UK targets
Ransomware attack on a computer
Ransomware attacks surged in 2024 as hackers looked to strike faster than ever
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
Less than half of ransomware incidents end in payment - but you should still be on your guard
ransomware avast
Hackers spotted using unsecured webcam to launch cyberattack
Latest in Security
An American flag flying outside the US Capitol building against a blue sky
The FCC is creating a security council to bolster US defenses against cyberattacks
Image depicting hands typing on a keyboard, with phishing hooks holding files, passwords and credit cards.
Microsoft warns about a new phishing campaign impersonating Booking.com
Ransomware
Microsoft uncovers sleuthy new XCSSET MacOS malware campaign
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Meta warns of worrying security flaw hitting open source type software
Hand holding smartphone and scan fingerprint biometric identity for unlock her mobile phone
Biometrics add another layer of security to passwordless authentication
Data leak
Hacked Tata Technologies data leaked by ransomware gang
Latest in News
An image of the Samsung Galaxy S25 Ultra from a hands-on event
Samsung Galaxy S26 Ultra could resurrect an intriguing camera feature
Eurocom Raptor X18
At $15,000, this massive 256GB RAM laptop makes Apple's MacBook Pro look affordable, tiny and very, very slow
Cristin Milioti in Black Mirror season 7
Netflix launches trailer for Black Mirror season 7, giving us a look at its first-ever sequel episode and an unexpected returning character
A graphic of the PC Gaming Show
Get ready for a bounty of PC games on June 8, as the PC Gaming show is back
A close up of The Daily podcast from Pocket Casts' web page
‘Podcasting shouldn’t be locked behind walled gardens’: Pocket Casts slams Spotify and makes its web player free to all
A smartphone on a sofa showing the WhatsApp, Telegram and Signal apps
Forget AI – WhatsApp is planning a simple messages feature that could be its most useful upgrade in years