REvil's infrastructure and websites are offline, including its data leak sites, less than two weeks after attacking 1,500+ businesses with ransomware via Kaseya
The infrastructure and websites for the REvil ransomware operation have mysteriously gone offline as of last night.
BleepingComputerLawrence Abrams
Context & Ripple Effects
The outage follows REvil's use of a Kaseya software update to compromise managed service providers, a distribution path that exposed thousands of downstream customer environments. REvil subsequently claimed a $70 million decryptor demand, making the availability of its leak and payment-facing infrastructure central to the pressure campaign.
REvil immediately loses its public data-leak and web infrastructure, interrupting the channels used to publish stolen data and sustain pressure on Kaseya-related victims.
Kaseya and affected companies can continue recovery through Kaseya's stated universal decryptor rather than relying on contact with REvil's now-unavailable sites.
Second-order effects
The outage reduces the immediacy of REvil's public leak threat for affected businesses, while forcing incident-response teams to rely on Kaseya's recovery process and their own restoration work.
The later reappearance of REvil's site means law-enforcement and security teams must treat infrastructure seizures or outages as operational disruptions, not proof that a ransomware group has been eliminated.
Third-order effects
The REvil sequence points to ransomware infrastructure as a recurring enforcement target: disrupting payment and leak-site operations can constrain a gang even when its underlying operators may reconstitute services.
If multi-country operations increasingly target these services, ransomware groups will face pressure to make their infrastructure more resilient, turning takedowns into an ongoing contest rather than a one-time remedy.
The trend: Ransomware enforcement is increasingly focused on repeatedly disrupting the online infrastructure that turns an intrusion into an extortion business.
Now that one of the most prolific ransomware gangs of all time is suddenly off the internet, cautiously optimistic experts urge everyone to avoid jumping to conclusions. It's too early to know what's going on. But the timing is impossible to ignore. https://www.technologyreview.c…
The ransomware crew known as REvil has existed for years in the booming cybercrime underground. A whopping 42% of all recent ransomware attacks trace back to this gang that suddenly disappeared from the internet Tuesday morning. https://www.technologyreview.com/ ...
“I don't have anything further to share on that,” Deputy Press Secretary Karine Jean-Pierre says when asked about REvil's sites suddenly going dark. The Russian ransomware gang was behind hack of JBS beef producers, etc. Unclear if US govt or Putin took them out, or not. https://…
Yep. This looks like REvil either went on vacation, they plan to rebrand, or the takedown wasn't particularly legal (if you know what I mean). https://twitter.com/...
It's early, but REvil is down. Maybe for the count. With no further context, this could mean almost anything: they bit off more than they could chew and are laying low after their big campaign after the 4th, they were pwned by @US_CYBERCOM, the FSB finally shut them down. https:/…
Your computer have been infected! Your documents, photos, databases and other files encrypted To decrypt your files you need our special software You can do it right now. Follow instructions below CYBERCOM-Decryptor price: > surrender at US embassy https://twitter.com/...
LOL... their sites were live and working right before this tweet. I went there to look at the Hx5 leak. Am I the last person who accessed their site? 😅 https://twitter.com/...