REvil: Governments Said to Turn Tables on Ransomware Gang by Pushing It Offline

A leadership figure known as "0_neday "said REvil's servers had been hacked by an unnamed party.

Advertisement
By Reuters | Updated: 22 October 2021 12:49 IST
Highlights
  • The Colonial attack used encryption software called DarkSide
  • Following the attack on Kaseya, FBI obtained a universal decryption key
  • Reliable backups are one of the most important defences

US government attempts to stop REvil accelerated after the group compromised US software company Kaseya

The ransomware group REvil was itself hacked and forced offline this week by a multi-country operation, according to three private sector cyber experts working with the United States and one former official.

Former partners and associates of the Russian-led criminal gang were responsible for a May cyberattack on the Colonial Pipeline that led to widespread gas shortages on the US East Coast. REvil's direct victims include top meatpacker JBS. The crime group's "Happy Blog” website, which had been used to leak victim data and extort companies, is no longer available.

Officials said the Colonial attack used encryption software called DarkSide, which was developed by REvil associates.

Advertisement

VMWare head of cybersecurity strategy Tom Kellermann said law enforcement and intelligence personnel stopped the group from victimising additional companies.

Advertisement

"The FBI, in conjunction with Cyber Command, the Secret Service and like-minded countries, have truly engaged in significant disruptive actions against these groups,” said Kellermann, an adviser to the US Secret Service on cybercrime investigations. “REvil was top of the list.”

A leadership figure known as "0_neday," who had helped restart the group's operations after an earlier shutdown, said REvil's servers had been hacked by an unnamed party.

Advertisement

"The server was compromised, and they were looking for me," 0_neday wrote on a cybercrime forum last weekend and first spotted by security firm Recorded Future. "Good luck, everyone; I'm off."

US government attempts to stop REvil, one of the worst of dozens of ransomware gangs that work with hackers to penetrate and paralyse companies around the world, accelerated after the group compromised US software management company Kaseya in July.

Advertisement

That breach opened access to hundreds of Kaseya's customers all at once, leading to numerous emergency cyber incident response calls.

Decryption key

Following the attack on Kaseya, the FBI obtained a universal decryption key that allowed those infected via Kaseya to recover their files without paying a ransom.

But law enforcement officials initially withheld the key for weeks as it quietly pursued REvil's staff, the FBI later acknowledged.

According to three people familiar with the matter, law enforcement and intelligence cyber specialists were able to hack REvil's computer network infrastructure, obtaining control of at least some of their servers.

After websites that the hacker group used to conduct business went offline in July, the main spokesman for the group, who calls himself "Unknown," vanished from the internet.

When gang member 0_neday and others restored those websites from a backup last month, he unknowingly restarted some internal systems that were already controlled by law enforcement.

“The REvil ransomware gang restored the infrastructure from the backups under the assumption that they had not been compromised,” said Oleg Skulkin, deputy head of the forensics lab at the Russian-led security company Group-IB. “Ironically, the gang's own favorite tactic of compromising the backups was turned against them.”

Reliable backups are one of the most important defences against ransomware attacks, but they must be kept unconnected from the main networks or they too can be encrypted by extortionists such as REvil.

A spokesperson for the White House National Security Council declined to comment on the operation specifically.

"Broadly speaking, we are undertaking a whole of government ransomware effort, including disruption of ransomware infrastructure and actors, working with the private sector to modernise our defences, and building an international coalition to hold countries who harbour ransom actors accountable," the person said.

The FBI declined to comment.

One person familiar with the events said that a foreign partner of the US government carried out the hacking operation that penetrated REvil's computer architecture. A former US official, who spoke on condition of anonymity, said the operation is still active.

The success stems from a determination by US Deputy Attorney General Lisa Monaco that ransomware attacks on critical infrastructure should be treated as a national security issue akin to terrorism, Kellermann said.

In June, Principal Associate Deputy Attorney General John Carlin told Reuters the Justice Department was elevating investigations of ransomware attacks to a similar priority.

Such actions gave the Justice Department and other agencies a legal basis to get help from US intelligence agencies and the Department of Defense, Kellermann said.

"Before, you couldn't hack into these forums, and the military didn't want to have anything to do with it. Since then, the gloves have come off."

© Thomson Reuters 2021


Realme India CEO Madhav Sheth joins Orbital, the Gadgets 360 podcast for an exclusive wide-ranging interview, as he talks about the 5G push, Make in India, Realme GT series and Book Slim, and how stores can improve their standing. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Microsoft Azure Outage: What Caused the Issue, How It Was Resolved
  2. Gemini 3 AI Model Will Be Released Soon, Says Google CEO Sundar Pichai
  3. Top OTT Releases of the Week: Kantara Chapter 1, Lokah Chapter 1, Idli Kadai, and More
  4. Oppo Find X9 Series Confirmed to Be Available in India via Flipkart
  5. Vivo S50 Pro Mini Key Specifications Tipped Ahead of Launch
  6. Instagram Lets Some Users 'Tune' Their Reels Algorithm
  7. Vivo X300 Series Launching Today: Everything You Need to Know
  8. Grammarly Rebrands to Superhuman, Introduces New Agentic AI Assistant
  9. Stray is Coming to PS Plus Essential Tier in November
  10. Nothing Phone 3a Lite Launched With Glyph Light At This Price
  1. Bitcoin’s Price Continues to Fall as Markets React to US Fed Rate Cut
  2. PS Plus Monthly Games for November Include Stray, EA Sports WRC 24 and Totally Accurate Battle Simulator
  3. Vivo S50 Pro Mini Key Specifications Tipped Ahead of China Launch; Could Debut Globally as Vivo X300 FE
  4. Google Confirms Gemini 3 AI Model Release Timeline: Tipped to Offer Improved Reasoning
  5. Google Brings Major Changes to Play Store Operations in the US After Epic Games Ruling
  6. Grammarly Rebrands to Superhuman, Introduces New Agentic AI Assistant
  7. Microsoft Azure Services Restored After Global Outage: What Caused the Issue, How It Was Resolved
  8. Microsoft CEO Satya Nadella Will Reportedly Visit India in December; Could Address Two AI Conferences
  9. Gemini for Home Voice Assistant Early Access Rollout Begins: Check Compatible Speakers, Displays
  10. Instagram Tests New Feature That Lets Users Customise Their Reels Algorithm
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.