Sigma Watch is free and independent. If it saves you time, keep it running. ☕ Buy me a coffee
SigmaWatch
Ransomware

REvil

Ransomware Needs review 15 detections found
This entry hasn't been reviewed yet. It was auto-detected from the MITRE ATT&CK catalog because it self-identifies as ransomware-type malware, but no one has curated a full summary or double-checked its reference links. Treat the details below as a starting point, not a verified profile.

Also known as: REvil, Sodin, Sodinokibi

Auto-detected from the MITRE ATT&CK catalog on 2026-09-28 (S0496) - this entry has not been reviewed or curated yet. See the MITRE ATT&CK link below for what's currently known; a proper summary and authoritative eradication references are pending.

Detection & eradication references

Curated links to authoritative sources — MITRE ATT&CK, CISA advisories, law-enforcement takedown announcements, and vendor threat-intel writeups — for removal, remediation, and further technical detail. Sigma Watch does not publish its own removal steps here, since malware behavior and tooling change too fast for a static write-up to stay reliably accurate.

Detection rules

Source Rule Status Updated
splunk Allow Network Discovery In Firewall production 2026-05-13
splunk Revil Registry Entry production 2026-05-13
splunk Revil Common Exec Parameter production 2026-05-13
splunk Msmpeng Application DLL Side Loading production 2026-05-13
splunk Modification Of Wallpaper production 2026-05-13
suricata ET HUNTING Possible REvil 0day Exploitation Activity Inbound rev 2 2024-03-08
suricata ET MALWARE REvil Exfil SFTP Certificate Inbound rev 2 2024-03-07
sigma PUA - Rclone Execution test 2023-03-05
sigma Renamed MegaSync Execution test 2023-02-03
sigma Deletion of Volume Shadow Copies via WMI with PowerShell test 2022-12-30
sigma Deletion of Volume Shadow Copies via WMI with PowerShell - PS Script test 2022-12-02
sigma REvil Kaseya Incident Malware Patterns test 2022-05-20
snort ET EXPLOIT Possible REvil 0day Exploitation Activity Inbound rev 1 2021-07-05
snort ET TROJAN REvil Exfil SFTP Certificate Inbound rev 1 2021-06-30
yara Revil_Ransomware — —