REvil Ransomware Group Dismantled by Russia at US Request

The arrests were a rare apparent demonstration of US-Russian collaboration at a time of high tensions between the two over Ukraine.

Advertisement
By Reuters | Updated: 17 January 2022 13:08 IST
Highlights
  • The United States welcomed the arrests
  • Cyberattack on the Colonial Pipeline led to widespread gas shortages
  • Russia told Washington directly of moves it had taken against the group

REvil has not been associated with any major attacks for months

Russia has dismantled ransomware crime group REvil at the request of the United States in an operation in which it detained and charged the group's members, the FSB domestic intelligence service said on Friday.

The arrests were a rare apparent demonstration of US-Russian collaboration at a time of high tensions between the two over Ukraine. The announcement came as Ukraine was responding to a massive cyber attack that shut down government websites, though there was no indication the incidents were related.

The United States welcomed the arrests, according to a senior administration official, adding "we understand that one of the individuals who was arrested today was responsible for attack against Colonial Pipeline last spring."

Advertisement

A May cyberattack on the Colonial Pipeline that led to widespread gas shortages on the US East Coast used encryption software called DarkSide, which was developed by REvil associates.

A police and FSB operation searched 25 addresses, detaining 14 people, the FSB said, listing assets it had seized including 426 million (roughly Rs. 40 crore), $600,000 (roughly Rs. 4 crore), 500,000, computer equipment and 20 luxury cars.

Advertisement

A Moscow court identified two of the men as Roman Muromsky and Andrei Bessonov and remanded them in custody for two months. Muromsky could not be reached for comment and his phone was off. Reuters could not immediately reach Bessonov.

Two Muscovites told Reuters Muromsky was a web developer who had helped them with websites for their businesses.

Advertisement

Russia told Washington directly of the moves it had taken against the group, the FSB said. The US Embassy in Moscow said it could not immediately comment.

"The investigative measures were based on a request from the ... United States," the FSB said. "... The organised criminal association has ceased to exist and the information infrastructure used for criminal purposes was neutralised."

Advertisement

The REN TV channel aired footage of agents raiding homes and arresting people, pinning them to the floor, and seizing large piles of dollars and Russian roubles.

The group members have been charged and could face up to seven years in prison, the FSB said.

A source familiar with the case told Interfax the group's members with Russian citizenship would not be handed over to the United States.

The United States said in November it was offering a reward of up to $10 million (roughly Rs. 75 crore) for information leading to the identification or location of anyone holding a key position in the REvil group.

The United States has been hit by a string of high-profile hacks by ransom-seeking cybercriminals. A source with direct knowledge of the matter told Reuters in June that REvil was suspected of being the group behind a ransomware attack on the world's biggest meat packing company, JBS SA.

Washington has repeatedly accused the Russian state in the past of malicious activity on the internet, which Moscow denies.

REvil has not been associated with any major attacks for months.

John Shier, a threat researcher at the UK-based Sophos cybersecurity company, said there was no independent confirmation the self-identified leaders of the "defunct" group had been arrested.

"If nothing else, it serves as a warning to other criminals that operating out of Russia might not be the safe harbor they thought it was," he said.

'Normal programmer'

A former client of Muromsky who only gave the name Sergei described him as a regular worker who did not appear wealthy.

Sergei runs a shop called Motohansa selling motorcycle spare parts. Muromsky created its website and supported it for some time charging him around RUB 15,000 (roughly Rs. 14,700) per month, he said.

"He is a smart person and I can imagine that if he wanted to do it (hacking) he could, but he charged very little money for his services. Several years ago he had a Rover car. That's not an expensive car at all," Sergei said.

Muromsky is in his thirties and was born in Anapa in Russia's south, he said. "He worked as a normal programmer."

Another client, Adam Guzuyev, described Muromsky as "a regular normal worker" who proved unable to install all the features Guzuyev wanted on his website.

"He earned no more than RUB 60,000 (roughly Rs. 60,000). I can't say he has genius abilities," he said, adding Muromsky spent three months working on his website.

© Thomson Reuters 2022


Why are Galaxy S21 FE and OnePlus 9RT launching now? We discuss this on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: REvil
Advertisement

Related Stories

Popular Mobile Brands
  1. Samsung Galaxy S26 Ultra, Galaxy S26 Pro Charging Speed Leaked
  2. iOS 26 Update Brings These New Features to AirPods Pro 3, Pro 2, AirPods 4
  3. iPhone 17 Pro Max Cosmic Orange Variant Out of Stock in the US, India: Report
  4. Amazon Sale 2025: Early Deals on Smartphones
  5. Oppo F31 Pro+ 5G Review
  6. MediaTek Confirms Dimensity 9500 Launch Date; Timeline to Its First 2nm Chip
  1. France Could Block Crypto Firms With MiCA Licenses Due to Enforcement Gap Concerns
  2. Oppo Find X9 Pro With Dimensity 9500 SoC Scores 4 Million Points on AnTuTu; Spotted on Geekbench
  3. Xiaomi 17 Pro Design Render Gives Us a Good Look at Its Leica-Branded Rear Cameras, Secondary Display
  4. Clair Obscur: Expedition 33 Has Sold 4.4 Million Copies in Less Than Six Months of Launch
  5. Materialists Now Streaming on Netflix: What You Need to Know About Dakota Johnson’s Starrer Movie
  6. The Trial Season 2 OTT Release Date: When and Where to Watch Kajol’s Legal Drama Series Online
  7. Ghaati OTT Release Reportedly Revealed Online: When and Where to Watch Anushka Shetty-Starrer Movie Online?
  8. American Express Launches NFT Passport Stamps to Commemorate Travel Memories
  9. Huawei Watch GT 6, GT 6 Pro Price, Specifications Leak Ahead of September 19 Launch: Report
  10. iPhone 17 Pro Max in Cosmic Orange Colourway Reportedly Out of Stock in the US, India
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.