惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

The GitHub Blog
The GitHub Blog
阮一峰的网络日志
阮一峰的网络日志
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Apple Machine Learning Research
Apple Machine Learning Research
小众软件
小众软件
博客园 - 司徒正美
Last Week in AI
Last Week in AI
爱范儿
爱范儿
罗磊的独立博客
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
博客园_首页
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
The Cloudflare Blog
雷峰网
雷峰网
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
WordPress大学
WordPress大学
Jina AI
Jina AI
人人都是产品经理
人人都是产品经理
量子位
V
V2EX
博客园 - 叶小钗
宝玉的分享
宝玉的分享
T
Tailwind CSS Blog

Intel 471 Blog

TeamPCP Supply Chain Attacks Turning Geopolitical Tension into Actionable Intelligence CVE-2025-68613: Zerobot botnet exploits critical vulnerability impacting n8n AI orchestration platform Introducing Cyber Threat Exposure Bundle: A Unified Approach to External Risk CVE-2026-20127: Critical Cisco SD-WAN vulnerability exploited in wild Handala Threat Group OpenClaw: A viral AI assistant and a magnet for infostealer malware and ClickFix trickery Israeli, US strikes against Iran triggers a surge in hacktivist activity CVE-2026-1731: Finding a critical RCE in an age of AI-driven vulnerability research Born to bypass MFA: Taking down Tycoon 2FA The UK Cyber Security Resilience Bill How AI and the human advantage beat tomorrow’s threats Winter Olympics 2026: Hacktivism Surges Ahead of Protests and Suspected Sabotage How Threat Hunting and “Good” Metrics Help The Business Likely fake ransomware operator 0APT causes panic — Our analysis Hunting APTs: from state policy to TTPs CrazyHunter Ransomware DevMan Ransomware Introducing HUNTER Tuning: a New Tool for Driving Behavioral Threat Hunt Detections Battling check fraud in the U.S. Gootloader Malware Update Shai-Hulud Worm 2.0 New FvncBot Android banking trojan targets Poland White Paper Preview: Black "Fraud Day” and Beyond — The Key Cyber Threats Facing the Retail Sector this Holiday Season Threat hunting case study: Detecting IAB activity Using deception to extract cyber threat intelligence Lynx Ransomware Qilin Ransomware Group ClickFix: Tricking users into installing infostealers Cybercrime Takedowns: Trust, Partnerships and Focus
What can we expect from the REvil arrests?
Intel 471 · 2022-01-25 · via Intel 471 Blog

It’s clear that the recent Russian law enforcement actions against REvil are a watershed moment in the fight against ransomware gangs. It’s a good thing that malicious threat actors are paying some sort of cost for their crimes, and it’s a positive step to see Russia take action against a pretty prominent group, given that the country hasn’t been inclined to do the same against other groups operating inside their borders. Yet, while the situation is still unfolding and there is lots more to be learned, we're definitely skeptical about the actual ramifications.

What we've learned

If the FSB did in fact arrest the “leader” of REvil as the press release states, it means REvil as the infosec community knows it is very much crippled, if not dead. Yet, there was little action from the group for months even before the arrests. REvil hasn’t been active since October 2021, and its own representatives on the cybercrime underground said it was ceasing operations.

The geopolitical ramifications have also come into play, given the current tension between Ukraine and Russia. We can’t dismiss the possibility that given the current situation, the Russian government sees an opening via ransomware arrests to make some effort (or semblance of effort) at diplomatic peace with the United States and the international community.

Moving forward

It’s likely that in the short term there will be increased operational security implemented by Ransomware-as-a-Service (RaaS) operators due to the attention from law enforcement agencies (LEAs) on a global scale. This increase in discretion will be unlikely to reduce the volume or cadence of malicious activity being carried out. Instead, we will likely see other groups seek to fill the void, as has been demonstrated in the past when prolific ransomware groups have been impacted by police activity or rule changes on underground forums. For example, when REvil terminated their operations in 2021, numerous other ransomware groups filled the void.

Even with REvil ceasing operations in October, ransomware incidents recorded by Intel 471 increased by 17.9 percent throughout the fourth quarter of 2021. As such, it’s unlikely that the REvil arrests will have any significant impact on the underground criminal economy or RaaS operations, with ransomware attacks likely to continue to increase against a wide variety of industries and sectors.

Nevertheless, it is possible that the seizure of large amounts of cryptocurrency during these raids will cause some fractures between malicious threat operators due to the loss of revenue. This is unlikely to be sustained as any impacted operators will likely try to replace their losses through joining other prominent RaaS groups or affiliates.

This single event likely won’t result in much change in the ransomware-as-a-service ecosystem. We don’t expect it will deter cybercriminals until a pattern of similar law enforcement actions emerge on the heels of this one – demonstrating the Russian government is seriously committed to cracking down on cybercriminal activity within their borders.