Ransomware
REvil
Ransomware
Needs review
15 detections found
This entry hasn't been reviewed yet. It was auto-detected from the MITRE ATT&CK catalog
because it self-identifies as ransomware-type malware, but no one
has curated a full summary or double-checked its reference links. Treat the details below as a starting point,
not a verified profile.
Also known as: REvil, Sodin, Sodinokibi
Auto-detected from the MITRE ATT&CK catalog on 2026-09-28 (S0496) - this entry has not been reviewed or curated yet. See the MITRE ATT&CK link below for what's currently known; a proper summary and authoritative eradication references are pending.
Detection & eradication references
Curated links to authoritative sources — MITRE ATT&CK, CISA advisories, law-enforcement takedown announcements, and vendor threat-intel writeups — for removal, remediation, and further technical detail. Sigma Watch does not publish its own removal steps here, since malware behavior and tooling change too fast for a static write-up to stay reliably accurate.
- REvil, Software S0496 — MITRE ATT&CK
Detection rules
| Source | Rule | Status | Updated |
|---|---|---|---|
| splunk | Allow Network Discovery In Firewall | production | 2026-05-13 |
| splunk | Revil Registry Entry | production | 2026-05-13 |
| splunk | Revil Common Exec Parameter | production | 2026-05-13 |
| splunk | Msmpeng Application DLL Side Loading | production | 2026-05-13 |
| splunk | Modification Of Wallpaper | production | 2026-05-13 |
| suricata | ET HUNTING Possible REvil 0day Exploitation Activity Inbound | rev 2 | 2024-03-08 |
| suricata | ET MALWARE REvil Exfil SFTP Certificate Inbound | rev 2 | 2024-03-07 |
| sigma | PUA - Rclone Execution | test | 2023-03-05 |
| sigma | Renamed MegaSync Execution | test | 2023-02-03 |
| sigma | Deletion of Volume Shadow Copies via WMI with PowerShell | test | 2022-12-30 |
| sigma | Deletion of Volume Shadow Copies via WMI with PowerShell - PS Script | test | 2022-12-02 |
| sigma | REvil Kaseya Incident Malware Patterns | test | 2022-05-20 |
| snort | ET EXPLOIT Possible REvil 0day Exploitation Activity Inbound | rev 1 | 2021-07-05 |
| snort | ET TROJAN REvil Exfil SFTP Certificate Inbound | rev 1 | 2021-06-30 |
| yara | Revil_Ransomware | — | — |