DETECTO/ThreatDossier
DashboardPricingThreatsRun Free ScanSign In
DETECTO/ThreatDossier

Security intelligence for MSPs, consultants, and businesses. Find breached credentials, compliance gaps, and exposed infrastructure before attackers do.

Product

  • Scan a Domain
  • Pricing
  • Dashboard
  • Sign In

Resources

  • Threat Intelligence
  • Ransomware Groups

Legal

  • Privacy Policy
  • Terms of Service

© 2026 DETECTO. All rights reserved.

Threats/Groups/Revil

Revil

Inactive

revil

First seen: 2019-08-26 00:00:00.000000Total victims: 98

Sodinokibi ransomware group also known as REvil (Ransomware Evil) operates as a ransomware-as-a-service (RaaS) model. After the group compromised his victims, they would threaten to publish the victim's sensitive data on their darknet blog named 'Happy Blog', unless the ransom is paid. The ransomware malware code used by REvil is pretty similar to the ransomware code used by DarkSide - a different threat actor. REvil group claims to steal information after a successful attack on the supplier of the tech giant Apple and stole confidential schematics of their upcoming products.

0Total Victims
0Countries Targeted
0Sectors Targeted
0Avg Attacks/Month

Activity Timelinelast 24 months

Top Targeted Sectors

Top Targeted Countries

Recent Victimsshowing 50 of 98

NameCountrySectorDate
kusd.eduUS—2022-11-28 20:34:41.644515
Sunknowledge Services Inc——2022-11-28 14:52:30.214654
medibank.com.auAU—2022-11-07 13:27:18.177659
Midea Group——2022-09-01 10:45:01.306893
Doosan Group——2022-08-02 18:39:59.243685
OptiProERP is a leading global provider of industry-specific ERP solutions for manufacture——2022-07-25 18:54:07.904400
Ludwig Freytag Group——2022-05-12 13:41:21.030758
Unicity International——2022-05-03 15:29:11.430449
Stratford University——2022-04-22 21:26:51.696558
Asfaltproductienijmegen——2022-04-21 03:04:48.602329
CYMZ——2022-04-21 02:00:22.470335
www.oil-india.com——2022-04-21 00:40:11.739219
Visotec Group www.visotec.com——2022-04-20 22:33:44.555617
PTT Exploration and Production - 720GB——2021-10-15 00:31:08.040931
ECKERD PERU S.A, INKAFARMA, MIFARMA——2021-10-08 07:43:54.293890
Join us on RAMP——2021-10-07 09:47:02.431284
Ronmor Holdings——2021-10-01 09:12:21.395876
Fimmick CRM Hong Kong (www.fimmick.com)——2021-09-30 10:15:09.108169
Fimmick CRM Honk Kong (www.fimmick.com)——2021-09-30 07:48:36.895586
Spiezle Architectural Group Inc.——2021-09-16 08:14:25.659034
ohiograting.com——2021-09-11 09:10:59.922906
Apex America——2021-09-09 23:46:55.436963
Allen, Dyer, Doppelt, & Gilchrist, P.A.——2021-09-09 23:46:55.432405
Betenbough Homes——2021-09-09 23:46:55.427712
CEC Vibration Products——2021-09-09 23:46:55.422526
ENPOL LLC——2021-09-09 23:46:55.417367
Iaffaldano, Shaw & Young LLP——2021-09-09 23:46:55.412701
angstrom automotive group——2021-09-09 23:46:55.408132
Agile Property Holdings——2021-09-09 23:46:55.403349
Möbelstadt Sommerlad——2021-09-09 23:46:55.398657
Gosiger——2021-09-09 23:46:55.393853
neroindustry.com——2021-09-09 23:46:55.388352
kuk.de / KREBS + KIEFER / 500GB——2021-09-09 23:46:55.383358
KASEYA ATTACK INFO——2021-09-09 23:46:55.378430
Daylesford - BHoldings - Bamford - The Wild Rabbit——2021-09-09 23:46:55.373636
Hx5, LLC——2021-09-09 23:46:55.368999
inocean.no / 2000 GB——2021-09-09 23:46:55.364385
Primo Water——2021-09-09 23:46:55.359664
lstaff.com / atworksprofessional / atworks.com——2021-09-09 23:46:55.354072
South Carolina Legal Services breach——2021-09-09 23:46:55.349375
ensingerplastics.com——2021-09-09 23:46:55.344645
Kaseya clients—Information Technology2021-07-02 00:00:00.000000
University Medical CenterUSHealthcare and Public Health2021-06-28 00:00:00.000000
FujifilmJPHealthcare and Public Health2021-06-01 00:00:00.000000
JBS (meat processor)—Food and Agriculture2021-05-30 00:00:00.000000
Sol OriensUSNuclear Reactors, Materials, and Waste2021-05-01 00:00:00.000000
Brazil's Tribunal de Justiça do Estado do Rio Grande do SulBRGovernment Facilities2021-04-28 00:00:00.000000
Apple MacBook via supplier Quanta Computer—Information Technology2021-04-20 00:00:00.000000
AsteelflashFRCritical Manufacturing2021-04-01 00:00:00.000000
Pierre FabreFRChemical2021-03-31 00:00:00.000000

Data from ransomware.live