Darket Diaries
Darket Diaries

126: REvil

REvil is the name of a ransomware service as well as a group of criminals inflicting ransomware onto the world. Hear how this ransomware shook the world. A special thanks to our guest Will, a CTI researcher with Equinix. Sponsors Support for this show comes from Zscalar. Zscalar zero trust exchange

Featured Speakers

Jack Rhysider Host

Topics Discussed

Episode Summary

Executive Summary: The episode contrasts an absurd identity-theft scam involving fake rideshare and delivery driver accounts with a deeper dive into R-Evil, a Russian-speaking ransomware-as-a-service gang that evolved from GandCrab. It explains how the group bought access, used supply-chain and double-extortion tactics, targeted major organizations, laundered profits, and was eventually disrupted by U.S. indictments and Russian arrests amid geopolitical suspicion.

Main Topics: Identity theft scam using rideshare and delivery platforms (Priority: 4/5): A Brazilian man and his circle allegedly used stolen identities to create fake Uber/food-delivery driver accounts, sell or rent them, and launder proceeds before being arrested. Evolution from GandCrab to R-Evil (Priority: 5/5): The episode traces how GandCrab pioneered big-game ransomware and ransomware-as-a-service, then rebranded and evolved into R-Evil with more advanced extortion methods. Ransomware ecosystem and initial access brokers (Priority: 5/5): The discussion explains how criminals buy access into companies via underground forums, then deploy ransomware after reconnaissance and privilege escalation. R-Evil tactics and double/triple extortion (Priority: 5/5): R-Evil escalated beyond encryption to steal and leak data, and later DDoS victims to increase pressure to pay ransoms. Major victims and high-profile attacks (Priority: 5/5): The episode highlights attacks on Texas government entities, TravelX, JBS, a nuclear contractor, and especially the Kaseya supply-chain incident affecting many downstream customers. Law enforcement disruption and geopolitical uncertainty (Priority: 4/5): The FBI, DOJ, and later Russian authorities arrested suspected R-Evil figures, but the timing and motive of Russian action remain ambiguous and possibly politically motivated.

Key Arguments: Fake identity verification and stolen personal data can scale into organized fraud when paired with online marketplaces for illicit accounts. Ransomware succeeded because criminals combined access brokerage, OSINT, and automation with a service model that lowered the barrier to entry for affiliates. Big-game hunting shifted ransomware from opportunistic encryption to high-value corporate extortion, making large enterprises the main target. R-Evil’s profitability came from ransomware-as-a-service: affiliates performed intrusion work while the core group handled payment, decryptors, and infrastructure. Double extortion and DDoS added leverage, making victims pay not just to restore files but to avoid public data leaks and business disruption. Supply-chain attacks dramatically increased impact, as shown by Kaseya, where one compromise affected many downstream organizations. Law enforcement pressure mattered only when it became coordinated and international; indictments and seizures disrupted the group’s operations. Russian arrests of alleged R-Evil members may have been genuine, selective, or politically timed; the episode treats the motive with skepticism.

Data Points: Fake driver accounts created: Over 100 - Gustavo and his group allegedly made and sold phony rideshare/food-delivery driver accounts. People in the fraud ring: 5 - Gustavo, his girlfriend, and three friends formed the account-fraud team. R-Evil emergence: April 2019 - Threat intelligence analyst Will says R-Evil first appeared around this time. Ransomware era started: 2019 - GandCrab and then R-Evil operated in this period as ransomware-as-a-service businesses. Victims on R-Evil leak site: 282 companies - Companies that did not pay were published to R-Evil’s leak site. Estimated attacks by Europol: Thousands - The episode cites Europol as saying R-Evil launched thousands of attacks. R-Evil deployment scale: Approx. 175,000 computers - U.S. Attorney General Merrick Garland’s briefing on the Kaseya case. Ransom paid to TravelX: $2.3 million - Reported payment after R-Evil crippled the currency exchange company. Ransom demand to GSM Law: $42 million - At the time, described as the largest ransom demand ever publicly reported. Data claimed stolen from GSM Law: 756 GB - The gang allegedly exfiltrated data from the law firm. JBS ransom payment: $11 million - The meat producer paid after its operations were disrupted. Kaseya ransom demand: $70 million in Bitcoin - R-Evil’s demand after its supply-chain attack on MSP software. R-Evil revenue cited by DOJ: At least $200 million paid in ransom - Attorney General Garland’s remarks in the post-indictment briefing. Workers likely infected via Kaseya: About 1,500 networks - The episode says the Kaseya exploit hit roughly this many networks in one day. Russian arrests announced: 14 members - FSB said it detained 14 alleged R-Evil members in Russia. Assets seized in Russian arrests: 426 million rubles, $600,000, and €500,000 - Reported by the FSB during the January 2022 arrest operation. Cars seized: 20 expensive cars - Part of the Russian seizure in the R-Evil arrests. Funds seized by U.S.: $6.1 million - DOJ seized ransom proceeds tied to another alleged R-Evil attacker. R-Evil core team size estimate: 10-20 individuals - Will estimates the core business was run by a relatively small group.

Pivotal Quotes: "We are SunCrypt group. We hacked your company yesterday... Think about your future and your families." — SunCrypt voicemail (played by Jack Recider): Used to illustrate the intimidation style of ransomware gangs and the emotional pressure on victims. "If you hit a company and you're able to get them to basically agree to pay a $10 million ransom, we'll keep 60 million, you'll get 40 million." — Will: Explaining the affiliate revenue split in ransomware-as-a-service operations. "When Kaseya realized that some of their customers' networks were infected with ransomware, they immediately took action." — Christopher Wray: FBI director describing the coordinated response to the Kaseya supply-chain attack.

Implications: Ransomware now functions as an industrialized criminal economy built on access brokering, extortion, and service layers. Strong backups, rapid response, and coordinated law enforcement are essential, but supply-chain risk and payment incentives keep the threat highly adaptive.

🔓 Sign Up for Unlimited Episode Search

About Darket Diaries

Explore true stories of the dark side of the Internet with host Jack Rhysider as he takes you on a journey through the chilling world of hacking, data breaches, and cyber crime.

View all episodes from Darket Diaries