Cloud Consulting Companies

  • BIG Data & Analytics
  • CLOUD
  • Data Center
  • IOT
  • Machine Learning & AI
  • SECURITY
  • Server
  • BlockChain
  • Virtualization
You are here: Home / SECURITY / REvil affiliates offer hefty ransom discounts, data reveals

REvil affiliates offer hefty ransom discounts, data reveals

June 30, 2021 by cbn Leave a Comment

The REvil, or Sodinokibi, ransomware crew and its affiliates appear to have aggressively ramped up their attacks in June 2021, according to data obtained by LeMagIT, Computer Weekly’s French sister title.

LeMagIT found 35 total victims in the past 30 days, slightly more than in April, which is up 30% over the franchise’s most active periods, namely August and October of 2020, and February and March of 2021.

The number of pages on the crew’s dark web leak site gives an indication of the extent of the syndicate’s activity: it listed 356 victims as of 3 June 2021, and 383 as of 28 June, for a total of 27 new victims during the period. Eight seem to be missing, which may indicate they have paid a ransom, although the reality may be different.

Of the REvil/Sodinokibi samples collected during June, five appear to highlight negotiations that led to at least partial payment of a ransom, a success rate of around 20%. This is ‘better’ than the group’s affiliates achieved in April and May, but appears to have come at a cost – in the form of deep discounting.

In the first case analysed by LeMagIT, the initial ransom demand was for $500,000 but the payment made was just under $281,000. In a second incident, the negotiations opened at $50,000 but a deal was quickly reached for a ransom of $25,750. The third case is probably the most spectacular, with the cyber criminals making an initial demand of $300,000 but settling for only $50,000 – payment occurred four days after the start of the discussion.

The same phenomenon was observed in two other cases. The first resulted in a ransom payment of $17,467 instead of the $100,000 originally requested, following discussions that lasted almost a month. In the second case, the mobsters were satisfied with $15,300, after three weeks of negotiations, having demanded $90,000 to begin with.

These sums do appear to be somewhat low compared to other high-profile ransoms paid in recent months, but the victims also seem more inclined to resist – LeMagIT observed one negotiation initiated on the basis of a request for $2.5m, but the victim rapidly terminated discussions.

REvil message
String of messages from REvil encouraging victim to pay ransom

When asked at the start of June about its activity by a Russian-speaking threat intelligence specialist, a REvil representative nevertheless claimed the group was doing well, and said that demand for access to the gang’s ransomware-as-a-service (RaaS) programme was high, with eight candidates applying for a single spot.

The REvil crew is also apparently still investing in its RaaS platform, with the Linux version of its encryption tool – first announced in April and available since early May – now observed in the wild for the first time. This tool begins its work by shutting down all virtual machines (VMs) on the ESXi host on which it is deployed before then engaging encryption, as observed by Vitali Kremez of Advanced Intelligence.

But the gang could also have some links to other groups, possibly even several. Recent investigations by the SecureWorks team have found that the emergent LV ransomware is heavily based on Sodinokibi code – however, they do not address questions that may arise from the existence of two different leak sites for LV’s extortion operations, one of which has recently become unavailable, possibly temporarily.

Nor do these elements shed any light on the mystery that hangs over another ransomware campaign, known as Lorenz.sZ40 (apparently named for one of the Nazi cipher machines cracked at Bletchley Park during World War II). Though researchers at Intezer do not see any link in the binary code with REvil/Sodinokibi, the web interface for making ransom payments is nothing more than a copy of REvil’s, albeit lacking a live chat module.

Share on FacebookShare on TwitterShare on LinkedinShare on Pinterest

Filed Under: SECURITY

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Archives

  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018
  • November 2018
  • October 2018
  • September 2018
  • August 2018
  • July 2018
  • June 2018
  • May 2018
  • April 2018
  • March 2018
  • February 2018
  • January 2018
  • December 2017
  • November 2017
  • October 2017
  • September 2017
  • August 2017
  • July 2017
  • May 2017
  • April 2017
  • March 2017
  • February 2017
  • March 2016
  • October 2014

Recent Posts

  • Try the Simplest Thing First to Address Hybrid Network Performance Issues
  • Try the Simplest Thing First to Address Hybrid Network Performance Issues
  • What Federal Privacy Policy Might Look Like If Passed
  • What Federal Privacy Policy Might Look Like If Passed
  • Agility in DevOps: What’s Holding Enterprises Back?

Recent Comments

  • Purefit Keto Reviews on Are PDUs Your Best Platform for DCIM Instrumentation?
  • https://gemcr.org/ on 10 Things You Should Know About Deep Learning

Categories

  • BIG Data & Analytics
  • BlockChain
  • CLOUD
  • Data Center
  • IOT
  • Machine Learning & AI
  • SECURITY
  • Server
  • Uncategorized
  • Virtualization

Categories

  • BIG Data & Analytics (1,777)
  • BlockChain (409)
  • CLOUD (3,013)
  • Data Center (649)
  • IOT (1,963)
  • Machine Learning & AI (87)
  • SECURITY (1,439)
  • Server (1)
  • Uncategorized (2,015)
  • Virtualization (331)

Subscribe Our Newsletter

 Subscribing I accept the privacy rules of this site

Copyright © 2022 · News Pro Theme on Genesis Framework · WordPress · Log in