CrowdStrike says REvil's infrastructure and website is accessible on the dark web after it went offline in July
- Group's ‘Happy Blog’ shames companies with stolen data — Site and REvil infrastructure is accessible on dark web — The infamous criminal ransomware group behind …
Context & Ripple Effects
REvil went dark in mid-July, less than two weeks after its $70M bitcoin demand for a universal decryptor following the Kaseya supply-chain attack that hit 1,500+ businesses. CrowdStrike's new observation — that the gang's infrastructure and its shaming-focused 'Happy Blog' are reachable again on the dark web — is the first sign of whether that disappearance was voluntary retreat under heat or a pause.
The timing matters because REvil's leverage model runs through that leak site: it was the venue where the gang threatened to publish 4TB stolen from clean energy firm Invenergy, which publicly refused to pay. If Happy Blog is back, so is the extortion channel.
First-order effects
- Kaseya-attack victims whose data was exfiltrated face resumed publication risk on Happy Blog, reviving extortion pressure that paused when REvil's sites went offline in July.
- REvil's affiliate network regains its listing and negotiation storefront, the infrastructure needed to resume operations against new targets.
Second-order effects
- Corporate victims weighing the Invenergy-style refusal-to-pay stance must recalculate, since a live leak site restores the credibility of publication threats that an offline REvil could not enforce.
- Sustained visibility of the group's infrastructure hands law enforcement a stable target to monitor, raising the odds of coordinated disruption rather than relying on the gang staying dark.
Third-order effects
- If ransomware brands keep flickering offline and returning, the industry norm shifts toward treating these outages as pressure responses rather than retirements — pushing governments toward active disruption campaigns instead of waiting gangs out.
- Persistent leak-site economics reinforce the no-payment position taken by firms like Invenergy, since paying funds infrastructure that reliably comes back.
The trend: Ransomware groups are cycling between retreat and return under mounting law-enforcement and geopolitical pressure, making their infrastructure outages temporary rather than terminal.