Hacking Group revictimizes ransomware victim even if ransom was already paid

Cybersecurity news

Created: 2022-07-24
Tags: #fleeting


REvil (a.k.a Sodinokibi) is a Ransomware as a service (RaaS), meaning they are offering of pay-for-use malware.

Coveware (a company that specializes in ransomware recovery)
has seen incidents where victims who already paid were re-extorted by REvil a few weeks later with threats to release the same data. Some failed to keep their promises by publishing the data of victims who chose to pay or by showing fake evidence of data deletion.

The REvil representative, told that the group is looking into adopting other techniques, such as launching DDOS attacks to force the hand of organizations that suspend negotiations.

How Revil Works

After breaking in,
hackers use a variety of tools and techniques to

  • map the network,
  • perform lateral movement,
  • obtain domain administrator privileges,
  • deploy the ransomware on all computers to maximize the impact.

References

  1. 112Gi