FBI Seizes Cryptocurrency Worth $2.3 Million From REvil Ransomware Group Affiliate

The accused Russian citizen and REvil affiliate has been last traced to an address in St. Petersburg.

Advertisement
By Shomik Sen Bhattacharjee | Updated: 6 December 2021 12:02 IST
Highlights
  • The confiscated crypto was linked to payments made to REvil Group
  • The attacks were executed between April 2019 to July 2021
  • REvil Group has been linked to several high-profile attacks

REvil has been operating since April 2019

Photo Credit: Pexels/ Sora Shimazaki

US law enforcement seized 39.9 Bitcoins from an Exodus wallet, worth approximately $2.3 million (roughly Rs. 17.3 crore) from a Russian citizen suspected of being associated with infamous hacker group REvil, known for their ransomware attacks. The Federal Bureau of Investigation (FBI) in a complaint unsealed last week states that the wallet contained REvil ransom payments belonging to an affiliate identified as Aleksandr Sikerin, who has been found employing ransomware viruses to break into databases of American infrastructure facilities.

The complaint, first seen by Bleeping Computer, reveals that Sikerin — who is affiliated with REvil — was responsible for the ransomware attacks that generated about $200 million (roughly Rs. 1,504.76 crore) in payments from victims between April 2019 and June 2021. The cryptocurrency wallet that is now under the FBI's control is "traceable to ransomware attacks committed by Sikerin"

Sikerin, meanwhile, whose last-known address has been traced to the Russian city of Saint Petersburg, has been charged with multiple counts of conspiracy and money laundering. That said, law enforcement officials believe Sikerin is just an affiliate in the vast network of REvil gang.

Advertisement

Ransomware gang affiliates are responsible for frontline hacking work and stealing the data from victims' machines. They usually earn 70-80 percent of the ransom.

Advertisement

REvil, also known as Sodinokibi or Sodin, has been one of the most notorious ransomware groups of over the past couple of years. The group targets company networks using spam, exploits, exposed remote desktop services and hacked managed service providers (MSPs).

While the FBI does not indicate the online alias of the threat actor in its complaint, those over at Bleeping Computer have looked into the email address mentioned in it and found that the name 'engfog' is tied to a REvil affiliate known as 'Lalartu' aka Aleksandr Sikerin — who has named in the complaint.

Advertisement

The news break nearly a month after the US Justice Department charged a Ukraine national and a Russian in one of the worst ransomware attacks against American targets as per court filings.

An indictment back then accused Ukrainian Yaroslav Vasinskyi, who was arrested in Poland last month, of breaking into Florida software provider Kaseya over the July 4 weekend. From there, he and accomplices simultaneously distributed REvil ransomware to as many as 1,500 Kaseya customers, encrypting their data and forcing some to shut down for days, it said.

Advertisement

Vasinskyi is charged with breaking into the victim companies and installing encryption software, developed by the core REvil group. REvil directly handled the ransom negotiations and split the profits with affiliates like Vasinskyi.

REvil, also involved in an attack against top global meatpacker JBS SA, was intercepted in a joint operation, where authorities recovered $6 million (roughly Rs. 45.17 crore) in ransom payments.


Interested in cryptocurrency? We discuss all things crypto with WazirX CEO Nischal Shetty and WeekendInvesting founder Alok Jain on Orbital, the Gadgets 360 podcast. Orbital is available on Apple Podcasts, Google Podcasts, Spotify, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Revil, cryptocurrency, ransomware
Advertisement

Related Stories

Popular Mobile Brands
  1. New Aadhaar App Launched for Android and iOS, Brings These Features
  2. Motorola Edge 70 Ultra Specifications Leaked Online; Could Run on This Chipset
  3. Realme GT 8 Pro Aston Martin F1 Limited Edition Debuts With Racing-Inspired Design
  4. Apple MacBook Pro OLED Redesign Expected Only on M6 Pro and M6 Max Versions
  5. WhatsApp Rolling Out Media Hub to Some Desktop Users: Report
  6. Arc Raiders Has Hit Over 450,000 Concurrent Players on Steam
  7. Vivo Y500 Pro Goes Official With 7,000mAh Battery
  8. Oppo Announces Launch of Reno 15 Series in China for This Date
  9. iQOO 15 May Come With Five Years OS Upgrades, Seven Years Security Update
  10. Apple May Bring Several New Satellite Connectivity Features to iPhone
  1. Paytm Revamps App With Cleaner Interface, Adds New AI-Powered Features
  2. Vivo Y500 Pro With MediaTek Dimensity 7400 Chipset, 7,000mAh Battery Launched: Price, Specifications
  3. Xiaomi 17 Ultra Tipped to Launch With LOFIC Camera Technology, 200-Megapixel Periscope Lens
  4. Samsung Galaxy S26, Galaxy S26+ Camera and Battery Details Leak; Incremental Upgrades Expected
  5. Arc Raiders Reportedly Sells 2.5 Million Copies, Hits 450,000 Concurrent Players on Steam
  6. Honor X80 Tipped to Get 10,000mAh Battery, Snapdragon Chipset, More
  7. WhatsApp Rolling Out Media Hub to Easily Browse Shared Images, Videos and More Shared Across Chat: Report
  8. Microsoft Is Developing New AI Agents for Enterprises That Behave as Independent Users
  9. iQOO 15 to Come With Five Years OS Upgrades, Seven Years Security Update: Report
  10. Apple Reportedly Developing Satellite-Powered Maps, Photo Sharing via Satellite on iPhone
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.