On July 2, 2021, the Fourth of July holiday weekend, REvil (also known as Sodinokibi) deployed ransomware against Kaseya VSA, a remote monitoring and management platform used by managed service providers. By the following Monday, approximately 1,500 businesses across 17 countries had been encrypted - hit through the MSPs that used Kaseya, multiplying the impact of a single vulnerability exploitation. REvil demanded $70 million for a universal decryptor. It was the largest coordinated ransomware attack in history up to that point.
Three days later, on July 13, REvil's infrastructure went dark. The leak site, the payment portals, and the group's public-facing presence all vanished simultaneously with no explanation. The FBI, which had been investigating REvil and had obtained a universal Kaseya decryptor weeks before the attack, did not immediately release it - an unusual decision that generated significant controversy. When REvil came back in September 2021, an FSB operation in January 2022 arrested 14 alleged REvil members in Russia - an unprecedented act of cooperation with US law enforcement. Three months later, after Russia invaded Ukraine, those arrested members were released.
REvil's Operations: Scale and Targets
REvil emerged in 2019 as an apparent successor to GandCrab, a ransomware operation that announced its own retirement in June 2019 after claiming $2 billion in ransom payments. REvil used similar code and the same affiliate model - a RaaS operation where the core team provided the ransomware and infrastructure while affiliates conducted the attacks and shared revenue. REvil's core team took approximately 20-30% of each ransom; affiliates kept the rest.
The group targeted large organizations - what the industry calls "big game hunting" - rather than the mass deployment against consumers and small businesses that earlier ransomware had used. Large targets meant larger ransoms: REvil's demands frequently ran from hundreds of thousands to tens of millions of dollars. Their targets included Travelex (currency exchange, January 2020, $6 million ransom paid), Grubman Shire Meiselas and Sacks (celebrity law firm, May 2020, published documents related to Lady Gaga and Donald Trump among others), Acer (Taiwan computer manufacturer, March 2021, $50 million demand), and Apple's Quanta supplier (April 2021, MacBook schematics published).
JBS Foods, the world's largest meat processing company, was hit in June 2021 - two weeks before the Kaseya attack. JBS paid $11 million in Bitcoin to restore operations, one of the largest ransomware payments ever confirmed. The attack temporarily disrupted meat processing in the United States, Canada, and Australia, creating supply chain pressure that contributed to the Biden administration's characterization of REvil as a national security concern.
Kaseya: The Supply Chain Attack
The Kaseya VSA vulnerability exploited in July 2021 was a zero-day that had been discovered by Dutch security researcher Victor Gevers and reported to Kaseya approximately a week before the attack. Kaseya was in the process of developing and testing patches when REvil's affiliate struck. The timing - Fourth of July holiday weekend, when IT staff availability is minimal - appeared deliberate.
The VSA product is used by MSPs to remotely manage their clients' systems. An MSP using a compromised VSA server has agent software deployed on all of their clients' machines, with the ability to push software, execute scripts, and make system changes. By exploiting the VSA server, REvil's affiliate gained the ability to push ransomware directly to every endpoint the MSP managed - bypassing the individual organizations' security controls entirely, because the VSA agent had administrative access and was trusted software.
The cascading impact was the defining characteristic: the 1,500 businesses hit were not direct targets but were collateral impact of hitting the MSPs. A supermarket chain in Sweden (Coop) had to close hundreds of stores because its point-of-sale terminals had been encrypted through an MSP. Kindergartens in Sweden were encrypted. The scale of impact from a single initial exploitation point was novel even in a landscape of supply chain attacks.
The Decryptor and the FBI's Decision
The FBI had obtained a universal Kaseya decryptor several weeks before the Kaseya attack - reportedly through a law enforcement operation against REvil's infrastructure or through a confidential source. The decryptor could have unlocked all files encrypted in the Kaseya attack. The FBI did not immediately release it to victims.
The bureau's internal reasoning, disclosed in a later Washington Post investigation, was that they were preparing an operation against REvil's infrastructure and did not want to tip off the group that they had access to the decryptor before the operation could be executed. The operation that would have arrested or significantly disrupted REvil did not materialize - REvil went dark on its own on July 13 before the FBI's planned action. The decryptor was eventually released to victims in late July, approximately three weeks after the attack.
Kaseya victims criticized the FBI's decision: their systems had been offline for weeks, some had paid ransoms, and the bureau had held the means of recovery for reasons that ultimately produced no arrests. The incident raised significant questions about how law enforcement balances investigative interests against the immediate harm to victims of active attacks.
The July 13 Disappearance
REvil's July 13 infrastructure shutdown was abrupt and complete. The group's Tor hidden service (the "Happy Blog" leak site), payment portals, and backend infrastructure all went offline simultaneously. The criminal underground's reaction was split: some believed it was an FBI/government operation, some believed it was a deliberate retirement to avoid the increased law enforcement attention that the Kaseya and JBS attacks had attracted, and some speculated about internal conflict.
The White House had publicly attributed the JBS attack to Russia and pressed Russian President Vladimir Putin to take action against ransomware operators at the Geneva summit in June 2021. Biden had told Putin that "critical infrastructure" should be off-limits and suggested consequences if ransomware attacks from Russia-based actors continued. The timing of REvil's disappearance, two weeks after the Kaseya attack and in the context of this diplomatic pressure, was consistent with either Russian government pressure on the group to go quiet or a law enforcement operation.
Return, Then Russian Arrests
REvil returned in September 2021 using backup copies of their infrastructure. The group operated briefly before going quiet again. In January 2022, the Russian Federal Security Service (FSB) announced it had conducted raids against REvil members at the request of American authorities, detaining 14 people, seizing computers, cryptocurrency wallets, and approximately 600 million rubles. The US Department of Justice simultaneously announced charges against Ukrainian national Yaroslav Vasinskyi (arrested in Poland) for the Kaseya attack, and Russian national Yevgeniy Polyanin for attacks against Texas businesses.
The FSB cooperation was genuinely unprecedented. Russia has historically refused to prosecute or extradite cybercriminals who operate against foreign targets and respect an unwritten rule about not targeting Russian organizations or infrastructure. The January 2022 arrests represented a departure from this pattern, apparently in response to sustained US diplomatic pressure following the Colonial Pipeline and Kaseya attacks.
The cooperation ended immediately when Russia invaded Ukraine in February 2022. The detained REvil members were released. Russia halted the criminal proceedings. The brief window of US-Russia cybercrime cooperation closed, and the underlying dynamic - Russian tolerance of ransomware operators who avoid domestic targets - reasserted itself.