Ransomware group

Revil ransomware: victims and leak site activity

The Revil ransomware group has listed 13 victims on its leak site since April 2022; its latest post is from 28 November 2022. Most affected countries: Australia and United States. Most targeted sector: Manufacturing.

Total posts 13
First seen 2022-04-20
Latest post 2022-11-28
Countries hit 2

About Revil

Sodinokibi ransomware group also known as REvil (Ransomware Evil) operates as a ransomware-as-a-service (RaaS) model. After the group compromised his victims, they would threaten to publish the victim's sensitive data on their darknet blog named 'Happy Blog', unless the ransom is paid. The ransomware malware code used by REvil is pretty similar to the ransomware code used by DarkSide - a different threat actor. REvil group claims to steal information after a successful attack on the supplier of the tech giant Apple and stole confidential schematics of their upcoming products.

Leak site (Tor)
http://aplebzu47wgazapdqks6vrcv6zcnjppkbxbr6wketf56nf6aq2nmyoyd.onion/

Revil victims per year

13 2022

All 13 victims

Search every post in the full table.
Victim Country Sector Discovered
kusd.edu United States Education
Sunknowledge Services Inc Professional Services
medibank.com.au Australia Healthcare
Midea Group Manufacturing
Doosan Group Manufacturing
OptiProERP is a leading global provider of industry-specific ERP solutions for manufacture Technology
Ludwig Freytag Group Manufacturing
Unicity International Professional Services
Stratford University Education
Asfaltproductienijmegen Manufacturing
CYMZ
www.oil-india.com Energy & Utilities
Visotec Group www.visotec.com Manufacturing