/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

CrowdStrike says REvil's infrastructure and website is accessible on the dark web after it went offline in July

- Group's ‘Happy Blog’ shames companies with stolen data  — Site and REvil infrastructure is accessible on dark web  —  The infamous criminal ransomware group behind …

Bloomberg

Context & Ripple Effects

REvil went dark in mid-July, less than two weeks after its $70M bitcoin demand for a universal decryptor following the Kaseya supply-chain attack that hit 1,500+ businesses. CrowdStrike's new observation — that the gang's infrastructure and its shaming-focused 'Happy Blog' are reachable again on the dark web — is the first sign of whether that disappearance was voluntary retreat under heat or a pause.

The timing matters because REvil's leverage model runs through that leak site: it was the venue where the gang threatened to publish 4TB stolen from clean energy firm Invenergy, which publicly refused to pay. If Happy Blog is back, so is the extortion channel.

First-order effects

  • Kaseya-attack victims whose data was exfiltrated face resumed publication risk on Happy Blog, reviving extortion pressure that paused when REvil's sites went offline in July.
  • REvil's affiliate network regains its listing and negotiation storefront, the infrastructure needed to resume operations against new targets.

Second-order effects

  • Corporate victims weighing the Invenergy-style refusal-to-pay stance must recalculate, since a live leak site restores the credibility of publication threats that an offline REvil could not enforce.
  • Sustained visibility of the group's infrastructure hands law enforcement a stable target to monitor, raising the odds of coordinated disruption rather than relying on the gang staying dark.

Third-order effects

  • If ransomware brands keep flickering offline and returning, the industry norm shifts toward treating these outages as pressure responses rather than retirements — pushing governments toward active disruption campaigns instead of waiting gangs out.
  • Persistent leak-site economics reinforce the no-payment position taken by firms like Invenergy, since paying funds infrastructure that reliably comes back.

The trend: Ransomware groups are cycling between retreat and return under mounting law-enforcement and geopolitical pressure, making their infrastructure outages temporary rather than terminal.

Discussion

  • @campuscodi Catalin Cimpanu on x
    Breaking: REvil ransomware group returns following Kaseya attack The group's leak site and payment portal have come back online earlier today after an almost two-month absence. https://therecord.media/... https://twitter.com/...