Skip to main content

Hit by ransomware? Isolate affected systems now. Do not reboot or reformat.

SheMo Noransom舍末无勒

Ransomware family

REvil Ransomware Decryption & Data Recovery

  • Inactive
  • High
  • Free decryptor available

REvil (Sodinokibi) was the most damaging RaaS operation of 2019-2021, known for random per-victim extensions, [ext]-HOW-TO-DECRYPT.txt notes and the Happy Blog leak site, and for the JBS and Kaseya supply-chain incidents. Its infrastructure went dark in July 2021 and the crew collapsed after Russian arrests in early 2022; files encrypted before 13 July 2021 can be recovered with Bitdefender's free decryptor.

First seen
2019-04
File extensions
.[5-10位随机字符]
Ransom notes
[随机后缀]-HOW-TO-DECRYPT.txt
Affected platforms
Windows / Linux / VMware ESXi / NAS storage

Family profile

File extensions
  • .[5-10位随机字符]
Ransom notes
  • [随机后缀]-HOW-TO-DECRYPT.txt
Contact patterns
  • Tor (.onion) negotiation portal, unlocked with the per-victim key/UID from the note
  • Early builds also listed a clearnet gateway domain (decryptor.top and similar)
  • Happy Blog leak site on Tor, naming victims and posting sample data
  • Ransom quoted in Bitcoin or Monero with a doubling countdown
Aliases / versions
Sodinokibi、Sodin、GOLD SOUTHFIELD、PINCHY SPIDER、Happy Blog(泄露站名)
First seen
2019-04
Status
Inactive
Operational status
Operation shut down
Threat level
High
Affected platforms
  • Windows
  • Linux
  • VMware ESXi
  • NAS storage
Tags
  • Defunct
  • Ransomware-as-a-Service
  • Double extortion
  • Targets virtualization
  • Supply chain
  • Exploits vulnerabilities
  • RDP brute force
  • Phishing
  • Legacy family
Decryptor
Free decryptor available

A free official decryptor does exist, but with a hard time boundary. On 16 September 2021 Bitdefender, working with law enforcement, released a universal REvil/Sodinokibi decryptor (BDREvilDecryptor). It is now listed on No More Ransom together with a step-by-step guide.

Scope. It only recovers files encrypted before 13 July 2021 — the day REvil's entire infrastructure went dark. Victims of the July 2021 Kaseya VSA supply-chain campaign were served separately by a universal key handed to Kaseya by a third party.

Out of scope.

  • Samples deployed after 13 July 2021, including the April 2022 "REvil returns" wave.
  • Copycat builds derived from leaked or reused code, which can produce identical extensions and notes under a different key hierarchy.
  • Files that were re-encrypted, or encrypted a second time by another family.

Important. Eligibility depends on the encryptor build and the encryption date, not on the extension. Identify the build from three to five encrypted files plus the ransom note first, and only ever trial the decryptor on offline copies — never against original disks. We make no "100% decryption" claim.

Sources

Latest activity

  1. Germany's BKA named two Russian nationals as GandCrab/REvil leaders: Daniil Shchukin (alias UNKN) and Anatoly Kravchuk, linked to 130+ extortions of German firms and over $40M in losses. Both believed to be in Russia.

    Sources

Overview

REvil (Ransomware Evil, also tracked as Sodinokibi and Sodin) surfaced publicly in April 2019, first observed when attackers dropped the encryptor through the Oracle WebLogic deserialisation flaw CVE-2019-2725. Multiple vendors - Sophos/Secureworks CTU, CrowdStrike and Unit 42 - found near-identical string-decoding routines and URL-building logic shared with GandCrab, and the consensus is that REvil was GandCrab's continuation under the operator cluster tracked as GOLD SOUTHFIELD / PINCHY SPIDER.

It ran as ransomware-as-a-service: a core team supplied the encryptor, the negotiation portal and the Happy Blog leak site, while affiliates handled intrusion and deployment for a revenue share. 2020-2021 was its peak - the Grubman Shire Meiselas & Sacks law-firm breach, $50 million demands against Acer and Apple supplier Quanta, an $11 million payment from JBS in May 2021, and in July 2021 the Kaseya VSA zero-day (CVE-2021-30116) that reached the downstream customers of hundreds of MSPs in a single campaign with a $70 million ask. Unit 42 put the average payment across the cases it observed in the first half of 2021 at roughly $2.25 million.

Kaseya triggered unprecedented diplomatic and law-enforcement pressure. On 13 July 2021 every REvil site went offline without warning; in October a multinational operation took over its servers; in January 2022 Russia's FSB announced arrests and charges. The brand never genuinely returned - public leak-site trackers record the last posting on 28 November 2022, roughly a hundred victims in total (counts vary between trackers), and more than three years of silence since.

The legal reckoning continued. In May 2024 Ukrainian national Yaroslav Vasinskyi, the operator behind the Kaseya deployment, received 13 years and 7 months in the United States plus $16 million restitution. In October 2024 a Russian court sentenced four members to more than four years; in June 2025 those four walked free with pre-trial detention counted as time served. In April 2026 Germany's Federal Criminal Police Office (BKA) publicly named two Russian nationals as the heads of GandCrab and REvil.

What this means today. REvil is not a live threat, but it still turns up in incident response in three forms: legacy encrypted data that may qualify for free decryption, copycat samples that borrow its extension and note format, and intrusion paths it opened years ago that were never properly cleaned.

How to identify it

Extension. REvil uses no fixed extension. Each victim host receives a random 5-10 character alphanumeric suffix, so report.xlsx becomes report.xlsx.9781xsd4. Every encrypted file on that host shares the suffix, but it differs between hosts - which is why searching by extension so often fails for this family and the note has to be used instead.

Ransom note. The filename is built from that suffix - [random-ext]-HOW-TO-DECRYPT.txt, for example 88f2947s-HOW-TO-DECRYPT.txt - so its leading segment matches the encryption suffix exactly. The English text supplies a per-victim key/UID plus a Tor negotiation address; early versions also listed a clearnet gateway domain such as decryptor.top so victims could reach the portal without Tor.

Wallpaper. One of the most distinctive traits. REvil generates a grainy blue background with centred white text reading "You are infected! Read [random-ext]-HOW-TO-DECRYPT.txt!" - seeing that wallpaper is close to a positive identification on its own.

System-side artefacts.

  • Volume shadow copies deleted and Windows recovery disabled.
  • Session public-key configuration left in the registry.
  • Some builds accept a -smode argument that reboots into Safe Mode before encrypting, to evade endpoint protection.
  • On ESXi hosts, traces of esxcli force-killing every running VM, with vmdk files under /vmfs/volumes encrypted.

Bottom line. Random extension plus a HOW-TO-DECRYPT note plus the blue grainy wallpaper together attribute the family with high confidence. Whether the data is freely decryptable, however, depends on the encryption date and build, and copycat samples can look identical while using a different key hierarchy.

Infection vectors

REvil ran a multi-vector operation in which each affiliate brought its own tradecraft. The access routes that recur across public analyses are:

  • Internet-facing application and edge-device flaws. Oracle WebLogic CVE-2019-2725 (the earliest observed delivery), Pulse Secure VPN CVE-2019-11510 - which CISA explicitly linked to REvil in its top routinely exploited vulnerabilities advisory - and Fortinet FortiOS CVE-2018-13379.
  • Supply chain. In July 2021 the Kaseya VSA zero-day CVE-2021-30116 was used to push the encryptor from an MSP remote-management platform down to its customers en masse. This was REvil's most destructive campaign and the pattern enterprises should study hardest: compromise the outsourced IT or management platform and the whole estate falls at once.
  • Exposed RDP and credential brute force, followed by direct interactive logon with valid credentials.
  • Phishing and weaponised documents delivering a loader, then a post-exploitation framework.
  • Watering holes and compromised software distribution channels in the earlier period.
  • Lateral movement and privilege escalation. Credential dumping, then mass deployment via PsExec, scheduled tasks or GPO once the domain controller was taken.

Affiliates typically completed exfiltration and mapped the backup estate before detonating, choosing a weekend or holiday night. The value of this list today is not defending against REvil but recognising that LockBit, Akira and Qilin still use the same doors - the ones left open back then are usually still open.

Encryption behavior

Algorithms. File contents are encrypted with the Salsa20 stream cipher under a unique per-file key. The key hierarchy is entirely elliptic-curve based (Curve25519/ECDH): each file gets its own keypair, the file key is derived as SHA3-256 of the ECDH shared secret, and the corresponding public key and configuration are written alongside the encrypted data, while the session private key is stored encrypted under the operators' public key. Nothing can be reversed from ciphertext alone - the September 2021 free decryptor exists because law-enforcement action put key material in a partner's hands, not because the cryptography was broken.

Encryption scope is a build-time setting and has to be determined per sample. REvil's configuration carries a fast-encryption switch (recorded as fast / flag_fast in Kaspersky's Sodin analysis): when set, only the leading portion of each file is encrypted, capped at roughly 1MB; when unset, the file is encrypted in full. So the scope can differ between builds, and even between batches inside one incident. Large files may turn out to have only their headers overwritten, leaving real structural-repair headroom - or database files (MDF/LDF, DBF, ibd) and virtual disks (vmdk/vhdx) may be overwritten end to end. Do not assume either case: pull real encrypted files and inspect where ciphertext actually starts and stops (is the middle or tail of the file still recognisable plaintext structure?), then decide whether structural repair is viable.

Recovery inhibition. It runs vssadmin.exe Delete Shadows /All /Quiet to remove shadow copies and uses bcdedit to disable the recovery environment and boot failure policy (recoveryenabled No, bootstatuspolicy ignoreallfailures), while terminating database, mail and backup-agent processes holding files open.

Safe Mode and evasion. Some builds accept a -smode argument that reboots into Safe Mode before encrypting, bypassing endpoint agents that do not start there.

Linux / ESXi / NAS. An ELF64 encryptor surfaced in mid-2021 - a public sample was disclosed in late June 2021 - running 50 threads by default and taking a --path argument plus a silent-mode flag. It first uses esxcli to force-kill every running VM so vmdk files under /vmfs are not locked and corrupted during encryption, and it also targets NAS appliances.

Double extortion. REvil was one of the early drivers of the model: data was stolen before encryption and published or auctioned in stages on Happy Blog if no payment came.

Assess before you act

Recoverability assessment

REvil is one of the few families where the first question is a date, not a hash. We do not pay ransoms and do not negotiate; our work is technical recovery and forensics. Recoverability is assessed in this order:

1) The official free decryptor - the key path, with a hard boundary. Bitdefender's universal REvil/Sodinokibi decryptor, published in September 2021 and listed on No More Ransom, recovers files encrypted before 13 July 2021. Kaseya supply-chain victims were served by a separate universal key. So the first step is establishing when encryption happened: file modification times, event logs, backup timestamps and the ransom note's creation time all corroborate it. Inside that window this path usually delivers the highest recovery ratio. We validate on isolated copies before running at scale.

2) Backups, snapshots and shadow copies. Shadow copies are normally deleted and the recovery environment disabled, but offline and offsite backups, storage-layer snapshots on NAS/SAN/gateways, hypervisor snapshots, untouched copies on the backup server and cloud version history all deserve checking one by one. For samples outside the decryptor window this is typically the best available route. Never reattach backup media to a network that has not been cleaned.

3) Structural repair - outcome depends on the build, so measure it. REvil's encryption scope is set at build time by a fast-encryption switch: enabled, it covers only the leading portion of a file (around 1MB); disabled, it encrypts in full. There is therefore no single answer for this family on whether page-level extraction and structural rebuilds of databases and virtual disks will work - pull real encrypted files first, establish how far the ciphertext actually extends, and judge from that. Also worth examining: files caught mid-encryption, very large files beyond the encryptor's handling, and directories or file types it skipped. Conclusions must come from measurement, not from experience with other families.

4) Unencrypted copies and log replay. File-server recycle bins, endpoint caches, BI and reporting staging databases, ERP archive exports, database transaction logs and application audit logs frequently support reconstruction or point-in-time replay of critical records.

5) Low-level carving. Some deployments write the encrypted file and delete the original, leaving source data in unallocated clusters that raw sector scanning can recover. This requires stopping all writes to the affected volumes immediately.

6) Breach impact assessment. REvil ran double extortion, so even a clean decryption leaves the stolen copy outstanding. Establish the scope and timeline of exfiltration, drive internal notification and regulatory obligations from it, and rotate and notify around affected accounts, keys and customer records.

We commit to a verifiable assessment and a clearly bounded recovery scope. We never claim "100% decryption", and no technique guarantees full recovery.

Our response plan

Hit by REvil ransomware? What to do

  1. Containment and forensic preservation

    Isolate affected hosts and ESXi servers from production networks and storage paths, and disable suspect accounts and remote access. Do not reboot or power off - REvil session key material and configuration live in memory and the registry and are lost on restart. Image or snapshot the domain controller, backup server, hypervisor management hosts and any MSP or remote-management agent endpoints first; export logs from the firewall, VPN, Active Directory and any Kaseya-class management platform; and preserve three to five encrypted files, the original ransom note and the wallpaper bitmap.

  2. Family identification and dating the encryption

    Confirm REvil from the random extension, the [random-ext]-HOW-TO-DECRYPT.txt note, the blue-and-white wallpaper and the file trailer structure, then separate the Windows encryptor, the ESXi/Linux encryptor and any copycat variant. The decisive step for this family is dating the encryption: cross-check file modification times, shadow copy deletion time, security and system event logs, backup job records and the note's creation time to determine whether the incident falls inside the pre-13 July 2021 free-decryption window.

  3. Recoverability assessment and plan sign-off

    If the incident sits inside the window, trial the Bitdefender decryptor against real samples in an isolated environment and measure the success rate. If it does not, shift the focus to a full inventory of backups, storage and hypervisor snapshots plus sample repairs on the critical databases and virtual disks - remembering that REvil's encryption scope varies with the build between leading-portion-only and full-file, so repair headroom has to be established from the ciphertext distribution in real samples and conclusions must come from measurement, not from experience with other families. Assess the exfiltration scope in parallel. Deliver a written plan stating which systems go the decryption route, which rely on backup rollback, and which need carving or business-level reconstruction, with expected recovery ranges, timelines and priorities.

  4. Recovery execution and business verification

    All work happens on images or copies with the originals kept read-only. Restore in business priority order: domain controllers and identity first, then core databases such as ERP and MES, then file and mail systems. For ESXi, restore VMs from snapshots or backups where they exist and only then evaluate vmdk structural repair - never re-initialise the datastore. After each batch run integrity checks and business-side verification (reconciliation, report comparison, application start-up tests) and record everything in a traceable recovery manifest.

  5. Attribution, hardening and handover

    Reconstruct the full kill chain: whether entry came from an edge-device vulnerability, exposed RDP, phishing or an upstream IT outsourcing / remote-management platform; where credentials leaked; and the timing and volume of exfiltration, which drives regulatory reporting. Remove persistence, rogue accounts, scheduled tasks and GPO backdoors; reset credentials domain-wide and enforce MFA; close down RDP and management ports, segment the ESXi management network, and rework MSP and remote-support channels for least privilege and auditability; rebuild backups to a 3-2-1 design with immutable copies. Close with an incident report and a formal handover checklist.

Risk warning

What not to do

  • Do not reboot or power off affected hosts and ESXi servers - losing memory- and registry-resident session key material, processes and connections destroys both evidence and part of the recovery chance.
  • Do not run a downloaded decryptor against original disks just because "REvil has a free decryptor" - it only covers files encrypted before 13 July 2021, and a build or date mismatch can damage data further. Identify first, then trial on copies.
  • Do not delete the ransom note or encrypted samples, and do not rush to clean up "virus files" or change the wallpaper - the random extension, the note and the wallpaper are the primary evidence for family and timing.
  • Do not format, reinstall or rebuild RAID sets and storage pools; never re-initialise an ESXi datastore or create new VMs on the original LUN, or low-level carving becomes impossible.
  • Do not reconnect backup tapes, external drives or the backup server to an uncleaned network, and do not immediately restore the link to an upstream MSP or remote-management platform - that is exactly the path the Kaseya campaign used.
  • Do not try to contact the onion portal or pay: the operators disbanded years ago and the infrastructure is gone, so payment buys neither a key nor a counterparty.

Emergency response

Data already encrypted? Stop and let an engineer look first

We do not pay ransoms and we do not negotiate with attackers. Engineers run a free assessment first, then propose a recovery plan and a firm quote.

Related scenarios

Related industries

Similar families

FAQ

REvil Frequently asked questions

  • Can REvil / Sodinokibi encrypted files really be decrypted for free?

    Conditionally, yes. Bitdefender released a universal REvil/Sodinokibi decryptor in September 2021 with law-enforcement support, now listed on No More Ransom - but it only works on files encrypted before 13 July 2021, the day REvil's infrastructure went dark. Kaseya supply-chain victims had a separate universal key channel. Samples encrypted after that date, those from the April 2022 revival, and copycats reusing the same extension and note format are all out of scope. Eligibility turns on the encryption date and encryptor build, not the extension. We establish both, validate the success rate on isolated copies, and only then decide on a bulk run.

  • The extension is a random string - how do we confirm it is REvil?

    REvil generates a random 5-10 character alphanumeric suffix per host, so searching by extension rarely helps. Check three things instead. First, the note filename, shaped as [random-ext]-HOW-TO-DECRYPT.txt, whose leading segment exactly matches the encryption suffix. Second, the wallpaper: a grainy blue background with centred white text pointing at that note. Third, the key-wrapping structure in the encrypted file trailer and the session public key stored in the registry. All three lining up is a solid attribution, though copycats can look identical while using a different key hierarchy, so sample-level analysis still decides.

  • Is REvil still active - can we still be attacked by it?

    No. REvil's infrastructure went offline on 13 July 2021, its servers were taken over by a multinational operation in October 2021, and Russia arrested members in January 2022. Its leak site last named a victim on 28 November 2022, roughly a hundred in total, and has been silent for more than three years. In May 2024 the Kaseya operator received 13 years and 7 months in the US; in October 2024 a Russian court sentenced four members to over four years, who were released in June 2025 on time served; in April 2026 Germany's BKA publicly named two Russian nationals as the GandCrab and REvil leaders. Anything calling itself REvil today is far more likely to be legacy data or a copycat, and needs its own analysis.

  • If the decryptor does not apply, can REvil-encrypted databases and VMs still be recovered?

    Yes, but one thing has to be settled first: REvil's encryption scope is not fixed. Its build configuration carries a fast-encryption switch - enabled, only the leading portion of a file is encrypted (around 1MB); disabled, the file is encrypted in full. So you can neither assume "only a slice of the big file was touched, page-level repair will work" nor conclude "it is overwritten end to end, repair is hopeless". Pull real encrypted files, establish how far the ciphertext extends, and decide on structural repair from that. The realistic order is: offline and offsite backups plus storage-layer snapshots, then hypervisor snapshots, then untouched copies on the backup server, then point-in-time replay from transaction and application logs, then unencrypted copies (reporting staging databases, archive exports, endpoint caches), and finally carving unallocated space. Files caught mid-encryption, skipped directories and oversized files are still worth measuring. All of it requires stopping writes to the original volumes immediately.

  • Does the old data leak still matter, and what should we do about it?

    It does. REvil was an early driver of double extortion: data was exfiltrated before encryption and published or auctioned in stages on Happy Blog. Even a successful decryption leaves that copy in someone else's hands, and recycling old breach data for fresh extortion is not unusual. We do not pay ransoms or negotiate. The useful actions are: establish the scope and timeline of what left, drive internal notification plus regulatory and contractual obligations from that, rotate affected accounts, passwords, API keys and certificates, assess notification duties toward customers and partners, and re-audit whether the original intrusion path was ever properly cleaned - backdoors and credentials from that era are often still live.

  • We were hit through an IT outsourcer or remote-management platform - what extra steps apply?

    That is the Kaseya pattern, and three extra steps apply. First, suspend and isolate the upstream management channel - RMM or remote-support agents, jump hosts, dedicated VPN links - and do not restore connectivity until the upstream side is confirmed clean, or you risk a second push. Second, extend forensics upstream: the management platform's job dispatch records, agent logs and account audit trail are what reconstruct the kill chain, and they also underpin liability allocation and regulatory reporting. Third, rework the authorisation model: least privilege, separate credentials, enforced MFA and full command auditing on the MSP channel - a management agent should never hold unconditional estate-wide execution rights. We can run the joint upstream/downstream forensics and the hardening acceptance for that channel.