REvil Ransomware Group Dismantled by Russia at US Request

The arrests were a rare apparent demonstration of US-Russian collaboration at a time of high tensions between the two over Ukraine.

Advertisement
By Reuters | Updated: 17 January 2022 13:08 IST
Highlights
  • The United States welcomed the arrests
  • Cyberattack on the Colonial Pipeline led to widespread gas shortages
  • Russia told Washington directly of moves it had taken against the group

REvil has not been associated with any major attacks for months

Russia has dismantled ransomware crime group REvil at the request of the United States in an operation in which it detained and charged the group's members, the FSB domestic intelligence service said on Friday.

The arrests were a rare apparent demonstration of US-Russian collaboration at a time of high tensions between the two over Ukraine. The announcement came as Ukraine was responding to a massive cyber attack that shut down government websites, though there was no indication the incidents were related.

The United States welcomed the arrests, according to a senior administration official, adding "we understand that one of the individuals who was arrested today was responsible for attack against Colonial Pipeline last spring."

Advertisement

A May cyberattack on the Colonial Pipeline that led to widespread gas shortages on the US East Coast used encryption software called DarkSide, which was developed by REvil associates.

A police and FSB operation searched 25 addresses, detaining 14 people, the FSB said, listing assets it had seized including 426 million (roughly Rs. 40 crore), $600,000 (roughly Rs. 4 crore), 500,000, computer equipment and 20 luxury cars.

Advertisement

A Moscow court identified two of the men as Roman Muromsky and Andrei Bessonov and remanded them in custody for two months. Muromsky could not be reached for comment and his phone was off. Reuters could not immediately reach Bessonov.

Two Muscovites told Reuters Muromsky was a web developer who had helped them with websites for their businesses.

Advertisement

Russia told Washington directly of the moves it had taken against the group, the FSB said. The US Embassy in Moscow said it could not immediately comment.

"The investigative measures were based on a request from the ... United States," the FSB said. "... The organised criminal association has ceased to exist and the information infrastructure used for criminal purposes was neutralised."

Advertisement

The REN TV channel aired footage of agents raiding homes and arresting people, pinning them to the floor, and seizing large piles of dollars and Russian roubles.

The group members have been charged and could face up to seven years in prison, the FSB said.

A source familiar with the case told Interfax the group's members with Russian citizenship would not be handed over to the United States.

The United States said in November it was offering a reward of up to $10 million (roughly Rs. 75 crore) for information leading to the identification or location of anyone holding a key position in the REvil group.

The United States has been hit by a string of high-profile hacks by ransom-seeking cybercriminals. A source with direct knowledge of the matter told Reuters in June that REvil was suspected of being the group behind a ransomware attack on the world's biggest meat packing company, JBS SA.

Washington has repeatedly accused the Russian state in the past of malicious activity on the internet, which Moscow denies.

REvil has not been associated with any major attacks for months.

John Shier, a threat researcher at the UK-based Sophos cybersecurity company, said there was no independent confirmation the self-identified leaders of the "defunct" group had been arrested.

"If nothing else, it serves as a warning to other criminals that operating out of Russia might not be the safe harbor they thought it was," he said.

'Normal programmer'

A former client of Muromsky who only gave the name Sergei described him as a regular worker who did not appear wealthy.

Sergei runs a shop called Motohansa selling motorcycle spare parts. Muromsky created its website and supported it for some time charging him around RUB 15,000 (roughly Rs. 14,700) per month, he said.

"He is a smart person and I can imagine that if he wanted to do it (hacking) he could, but he charged very little money for his services. Several years ago he had a Rover car. That's not an expensive car at all," Sergei said.

Muromsky is in his thirties and was born in Anapa in Russia's south, he said. "He worked as a normal programmer."

Another client, Adam Guzuyev, described Muromsky as "a regular normal worker" who proved unable to install all the features Guzuyev wanted on his website.

"He earned no more than RUB 60,000 (roughly Rs. 60,000). I can't say he has genius abilities," he said, adding Muromsky spent three months working on his website.

© Thomson Reuters 2022


Why are Galaxy S21 FE and OnePlus 9RT launching now? We discuss this on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: REvil
Advertisement

Related Stories

Popular Mobile Brands
  1. Apple's iOS 26.1 May Launch on This Date, Followed By iOS 26.2 Beta Rollout
  2. Apple is Expected to Launch These Products Next Year
  3. Here Are the Best Smartphones Under Rs 20,000 With AMOLED Display
  4. Poco F8 Pro, F8 Ultra Set for Global Launch 'Really Soon', Tipster Claims
  5. Samsung Galaxy S26 Series Could Launch on This Date
  6. Rockstar Co-Founder Says GTA Games Won't Work if Set Outside the US
  7. Samsung Galaxy A57 Spotted on Company's Test Server With This Model Number
  8. Realme GT 8 Pro Aston Martin F1 Limited Edition Launch Date Revealed
  9. Bad Girl OTT Release Date Revealed: When and Where to Watch it Online?
  10. Oppo Reno 15 Series Might Launch in India Next Month
  1. Japan’s Akatsuki Spacecraft Declared Inoperable, Marking End of Dedicated Venus Missions
  2. NASA’s JWST Produces First-Ever 3D Map of Distant Planet WASP-18b
  3. Bad Girl OTT Release Date Revealed: Know When and Where to Watch This Tamil Movie Online
  4. Dhoolpet Police Station OTT Release: Know When and Where to Watch This Upcoming Crime Series Online
  5. Rockstar Games Co-Founder Says GTA Games Won't Work if Set Outside the US
  6. Iran Tackles Unauthorised Crypto Mining After 95 Percent of Bitcoin Mining Devices Found Operating Illegally
  7. Red Magic 11 Pro Launched Globally With Snapdragon Elite Gen 5, Slightly Smaller Battery: Price, Specifications
  8. Microsoft AI Chief Mustafa Suleyman Calls the Idea of Conscious AI ‘Absurd’: Report
  9. Poco F8 Ultra, Poco F8 Pro Global Launch Around the Corner, Tipster Claims
  10. India’s Smartphone Shipments Grew 5 Percent YoY in Q3 2025; Apple Enters List of Top 5 Phone Makers: Counterpoint
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.