MITRE ATT&CK G0115

REvil / Sodinokibi

View MITRE Group Page ↗
Aliases: Sodinokibi, Gold Southfield
Official Attribution Source: U.S. Department of Justice (N.D. Tex.) & Europol Operation GoldDust

Key Facts

Jurisdiction
Russian Federation
Geographic origin
Cases
2
Prosecution matters
Defendants
2
Indicted individuals
Sanctions
0
OFAC designations
  • Attributed Country: Russian Federation.
  • ATT&CK Group Reference: G0115 (REvil / Sodinokibi).
  • Linked to 2 primary court prosecution records.
  • Identified 2 individually charged operatives.

Primary ATT&CK Techniques Employed

ATT&CK Techniques Mapped to REvil / Sodinokibi Technique frequencies extracted from verified indictments for REvil / Sodinokibi. T1190 Exploit Public-Facing Application 1 incidents T1574.002 DLL Side-Loading 1 incidents T1486 Data Encrypted for Impact 1 incidents T1569.002 Service Execution 1 incidents T1082 System Information Discovery 1 incidents
Technique frequencies extracted from verified indictments for REvil / Sodinokibi.
ATT&CK Techniques Mapped to REvil / Sodinokibi
Technique Frequency
T1190 Exploit Public-Facing Application 1 incidents
T1574.002 DLL Side-Loading 1 incidents
T1486 Data Encrypted for Impact 1 incidents
T1569.002 Service Execution 1 incidents
T1082 System Information Discovery 1 incidents

Prosecution Cases Attributed to This Actor

sentenced 2021-08-11

U.S. v. Yaroslav Vasinskyi (Kaseya VSA / REvil Ransomware)

Ukrainian national and REvil ransomware affiliate responsible for deploying the ransomware attack that hijacked Kaseya VSA management software, instantly encrypting up to 1,500 downstream businesses on July 4th weekend.

5 techniques View case →
fugitive 2021-11-08

U.S. v. Aleksandr Sikerin & Yevgeniy Polyanin (REvil Operations)

International enforcement action against REvil ransomware money exchangers and operators, recovering $6.1 million in ransomware proceeds extorted from businesses and local governments across the United States.

1 techniques View case →