Threat actor reference

Classification follows the source dataset. Metadata is useful. It is not testimony.

Actor lineage

Global lineage directory
SodinokibiSodin

Overview

REvil and Sodinokibi are explicitly paired by DOJ and MITRE. MITRE models REvil as software rather than an ATT&CK group, so extortion.wiki does not invent a group mapping.

Documentary media

Known aliases

Evidence-backed names associated with this lineage record
AliasTypeFirst observedLast observedConfidenceSources
SodinokibiDOJ uses the combined name Sodinokibi/REvil; MITRE lists Sodinokibi as associated software. Malware name April 2019 Date not established Confirmed U.S. Department of Justice · MITRE ATT&CK
SodinMITRE associated-software name; this label describes the malware family, not necessarily every operator. Malware name April 2019 Date not established Confirmed MITRE ATT&CK

Historical timeline

Lineage and relationships

No evidence-backed relationship is currently recorded. Similar code, language, infrastructure style, or negotiation behavior is not enough on its own.

Predecessors

None established.

Successors

None established.

Splits and mergers

None established.

Suspected affiliate relationships

None established.

MITRE ATT&CK integration

No explicit MITRE ATT&CK group mapping is published for this source label. Software entries and fuzzy name matches are not promoted to group mappings.

External intelligence references

  1. Ukrainian Arrested and Charged with Ransomware Attack on KaseyaU.S. Department of Justice · law enforcement · primary authoritative
  2. REvil, Software S0496MITRE ATT&CK · MITRE ATTACK · authoritative secondary
  3. Yevgeniy Igorevich PolyaninFederal Bureau of Investigation · law enforcement · primary authoritative
  4. Privacy PolicyFederal Bureau of Investigation · publisher terms · context only

Confidence and evidence notes

Confidence applies to each individual alias, event, or relationship—not to the actor page as a whole. “Confirmed” requires explicit authoritative attribution or multiple strong independent sources. Moderate, low, disputed, and unknown entries retain the source's uncertainty. A malware-family name is not automatically an actor identity, and shared code or affiliates do not prove shared leadership.

Search within this collection

Negotiation records

Filter REvil records

Collection: 20 records · 1,065 messages

REvil negotiation record collection
Participants Source Archive status
20210709 1 REvil JSON Indexed
20210709 28 REvil, Victim JSON Indexed
20210630 42 REvil, Victim JSON Indexed
20210628 39 REvil, Victim JSON Indexed
20210622 52 REvil, Victim JSON Indexed
20210617 67 REvil, Victim JSON Indexed
20210616 31 REvil, Victim JSON Indexed
20210613 132 REvil, Victim JSON Indexed
20210609 58 REvil, Victim JSON Indexed
20210604 10 REvil, Victim JSON Indexed
20210603 63 REvil, Victim JSON Indexed
20210413 156 REvil, Victim JSON Indexed
20210407 15 REvil, Victim JSON Indexed
20210401 78 REvil, Victim JSON Indexed
20210331 23 REvil, Victim JSON Indexed
20210329 43 REvil, Victim JSON Indexed
20210320 13 REvil, Victim JSON Indexed
20201126 79 REvil, Victim JSON Indexed
20201104 63 REvil, Victim JSON Indexed
20201014 72 REvil, Victim JSON Indexed