https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • Complete 2023 MSP 501 Rankings
    • 2023 MSP 501 50-1
    • 2023 MSP 501 100-51
    • 2023 MSP 501 150-101
    • 2023 MSP 501 200-151
    • 2023 MSP 501 250-201
    • 2023 MSP 501 300-251
    • 2023 MSP 501 350-301
    • 2023 MSP 501 400-351
    • 2023 MSP 501 450-401
    • 2023 MSP 501 501-451
    • NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Channel Futures 20: Top Tech Providers
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2023 MSP 501
    • 2023 NextGen 101
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2024 CP Expo Call for Speakers
    • Channel Futures Leadership Summit
    • MSP Summit
    • CP Conference & Expo
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • Complete 2023 MSP 501 Rankings
    • 2023 MSP 501 50-1
    • 2023 MSP 501 100-51
    • 2023 MSP 501 150-101
    • 2023 MSP 501 200-151
    • 2023 MSP 501 250-201
    • 2023 MSP 501 300-251
    • 2023 MSP 501 350-301
    • 2023 MSP 501 400-351
    • 2023 MSP 501 450-401
    • 2023 MSP 501 501-451
    • NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Channel Futures 20: Top Tech Providers
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2023 MSP 501
    • 2023 NextGen 101
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2024 CP Expo Call for Speakers
    • Channel Futures Leadership Summit
    • MSP Summit
    • CP Conference & Expo
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Agents
  • Cloud Service Providers
  • Channel Partners Events
 Channel Futures

Security


Shutterstock

Start slideshow

REvil Ransomware Group Reemerges, Already Wreaking Havoc

  • Written by Edward Gately
  • September 10, 2021
There is no evidence suggesting there was a political link between the disappearance and reemergence of REvil.

The REvil ransomware group, which was behind the attack on Kaseya just before the July 4th weekend, is back after a brief disappearance.

Flashpoint’s threat intelligence team has observed new activity from the REvil ransomware group. The group posted twice on the illicit Russian-language forum Exploit to address and clarify what happened during the Kaseya-related key generation process and the human error that apparently caused the universal key to be leaked.

In the weeks following the attack, Kaseya said it acquired a universal decryptor allowing victims of the attack to unlock encrypted files for free.

In one of its Exploit posts, REvil explains how it lost control of the universal decryptor:

“Our encryption process allows us to generate either a universal decryptor key or individual keys for each machine. Then, in the process of generating the keys, we had to generate between 20 and 500 decryption keys for each [individual] victim [because the victims of the Kaseya attack all had networks of different sizes]. One of our coders misclicked and generated a universal key, and issued the universal decryptor key along with a bunch of keys for one machine.”

REvil Ransomware Group ‘Fully Operational’

According to Flashpoint, “for all intents and purposes, it appears that REvil is fully operational after its hiatus.”

“Evidence also points to the ransomware group making efforts to mend fences with former affiliates who have expressed unhappiness with the group’s disappearance,” it said.

Flashpoint cybersecurity and threat intelligence analysts said there is no evidence suggesting there was a political link between the disappearance and reemergence of REvil.

Also, in its latest posts, REvil says victims of the Kaseya attack paid $10 million in ransoms.

What Reemergence Means

Flashpoint's Maria Gershuni

Flashpoint’s Maria Gershuni

So what does the reemergence of REvil mean? We spoke with Maria Gershuni, global intel analyst II with Flashpoint.

Chanel Futures: What does this reemergence of REvil mean? Is it surprising that REvil is back?

Maria Gershuni: While this development is significant, it is not surprising. Flashpoint analysts have long observed chatter on illicit forums discussing a possible reemergence of the group. However, most chatter believed that the group would reemerge under a new name. They were wrong.

After REvil first disappeared, discussion circulated on whether the disappearance had geopolitical implications. Prompted by REvil’s attack, U.S. President Biden issued an ultimatum to Russian President Putin in a July 2021 phone call, telling his Russian counterpart to step up and deal with the ransomware collectives that are operating within Russian territory.

Researchers commonly believe that cybercriminals who operate in Russia receive safe harbor from domestic law enforcement in exchange for the criminals’ tacit agreement to not attack Russian entities. REvil’s disappearance, less than a week after the Biden-Putin phone call, seemed to point to the Russian government’s cooperation with U.S. requests and may have signaled a potential cyber rapprochement in dealing with cybercriminal organizations. The reemergence of REvil, however, puts a damper on hopes that Russia and the U.S. would cooperate to combat cybercrime.

Scroll through our gallery above for more of Gershuni’s comments and more cybersecurity news.

Want to contact the author directly about this story? Have ideas for a follow-up article? Email Edward Gately or connect with him on LinkedIn.
Tags: MSPs VARs/SIs Intelligence Artificial Intelligence Cloud Galleries Security Technologies

Most Recent


  • Cisco acquisition of Splunk gets partner reaction
    Partners Hope Splunk Keeps 'Pace of Innovation' in Cisco Acquisition
    All will be well if Cisco integrates Splunk the way it integrated Meraki, a partner told Channel Futures.
  • Broadcom-VMware and China
    Broadcom-VMware Hits Snag in China as IT Incurs Too-High Cloud Costs
    Our latest cloud news roundup features an acquisition update, looks at research you need to know, and more.
  • cloud marketplaces
    Haven’t Drunk the Cloud Marketplaces Kool-Aid? It’s About Time You Did
    The Ultimate Partner's Vince Menzione explains why channel partners (small ones, too) need to get on board.
  • Watching reality TV
    The Channel on Reality TV: Tech Advisor Shares Experience on Startup Show
    Going on a show for entrepreneurs showed how the technology advisor channel is one of the business world's "biggest secrets."

Leave a comment Cancel reply

-or-

Log in with your Channel Futures account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • Dell PowerScale appliances
    Dell Focused On Flexibility with Latest PowerScale Updates
  • Twenty, 20, SD-WAN providers
    The CF List: 20 Email Security Providers You Should Know
  • sase
    New Palo Alto SASE Solution Adds 5G-Friendly SD-WAN
  • Apple iPhone iOS
    Big iPhone, iPad Security Threat: Apple Update Blocks Sinister Spyware

Upcoming Events

View all

Channel Futures Leadership Summit

October 30, 2023 - November 2, 2023

Channel Partners Conference & Expo

March 11, 2024 - March 14, 2024

Channel Futures Leadership Summit 2024

September 17, 2024 - September 19, 2024

Galleries

View all

Broadcom-VMware Hits Snag in China as IT Incurs Too-High Cloud Costs

September 22, 2023

Cisco’s Splunk Acquisition ‘True Bombshell Move,’ Will Have Massive Impact on Cybersecurity

September 21, 2023

Cisco SMB Business Gets Updated Sales Coverage Model, New Investments

September 21, 2023

Industry Perspectives

View all

Why Conversational AI Matters for Your Customers and How It Can Boost Your Revenue

September 15, 2023

The 5 Ds that Lead to Unplanned Business Sales

September 13, 2023

Hot Generative AI Market Must ‘Cool Down’

August 28, 2023

Webinars

View all

MSP 501: Leadership in Cybersecurity

October 19, 2023

DE&I: Find the Balance that Works for You

September 7, 2023

Above and Beyond with the NextGen 101ers

August 30, 2023

White Papers

View all

6 UCaaS Reseller Challenges and How Real World Businesses Solved Them

February 1, 2023

Frost Radar: North American UCaaS Market, 2022

February 1, 2023

The Complete Guide to White-Label UCaaS for Reseller Success

February 1, 2023

Channel Futures TV

View all

Coffee with Craig and James Episode 129: ZLH Enterprises

Coffee with Craig and James Episode 128: Channel Partner Strategies Intelligence Service

August 25, 2023

Coffee with Craig and James Episode 127: Expereo, Movie Night Returns

August 18, 2023

Coffee with Craig and James Episode 126: ARG

July 28, 2023

MSP 501

The industry's largest and most comprehensive partner awards program.

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Galleries

Educational slide shows and images from live events.

Media Kit And Advertising

Want to reach our audience? Access our media kit.

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Events
  • Telecoms.com
  • MSP 501
  • Black Hat
  • IoT World Today
  • Omdia

WORKING WITH US

  • Contact
  • About Us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2023 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X