Monday, April 28, 2025
HomeCyber Security NewsREvil Ransomware Gang Suddenly Disappear - Dark Web Sites Are Down

REvil Ransomware Gang Suddenly Disappear – Dark Web Sites Are Down

Published on

SIEM as a Service

Follow Us on Google News

REvil is one of the well-known Ransomware Gangs from Russia which is popular for its earlier and recent ransomware attacks. Apart from this, the REvil ransomware gang mainly targets political figures and big tech companies.

However, all the websites that were associated with the REvil ransomware group have currently disappeared from the Internet. 

According to several web reports, all those websites that are associated with REvil Ransomware Gang are no longer accessible, and all kinds of communications have been discontinued. 

- Advertisement - Google News

REvil Ransomware Gang Suddenly Disappear

Apart from websites, the media that has been used by the group to communicate had also stopped. Even all the dark websites that are associated with the REvil ransomware group are now inaccessible.

Recently, REvil ransomware group has encrypted nearly 60 managed service providers (MSPs) and more than 1,500 individual businesses simply by utilizing a zero-day vulnerability in the Kaseya VSA remote management software.

This attack is one of the big attacks of REvil, and after implementing the attack, this ransomware gang has charged $70 million for a comprehensive decryptor for all victims that got affected by this attack but soon after the demand the group decreased the demanded price to $50 million.

Dismissal possibilities 

According to the law enforcement team, security experts have raised few dismissal possibilities, and here we have mentioned them below:-

  • It might happened, because initially, the United States has made a strong settlement to attack the servers of this group.
  • It might happened due to the discussion between Vladimir Putin and Biden, and as a result, Russia has taken few actions to follow the United States’ demands. All this has been done to stop mutual relations from starting to undergo due to repeated attacks.
  • It may also be possible that the REvil group itself has eliminated all of its websites. However, their attacks have obtained nearly 42%, and it’s becoming quite risky for them to implement further attacks, that’s why doing this will help them a lot, and later the attackers could appear again under a new name and with new victims.

However, REvil ransomware group was in the spotlight as last month, the group has attacked JBS, the world’s biggest supplier of beef and poultry, as well as the second-largest producer of pork.

Moreover, the analysts are still trying their best to find the possible reasons and the loopholes for such a situation. Even they have also claimed that there are many possibilities and they are striving to know all of them as soon as possible.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Advanced Multi-Stage Carding Attack Hits Magento Site Using Fake GIFs and Reverse Proxy Malware

A multi-stage carding attack has been uncovered targeting a Magento eCommerce website running an...

Hannibal Stealer: Cracked Variant of Sharp and TX Malware Targets Browsers, Wallets, and FTP Clients

A new cyber threat, dubbed Hannibal Stealer, has surfaced as a rebranded and cracked...

Rack Ruby Framework Vulnerabilities Let Attackers Inject and Manipulate Log Content

Researchers Thai Do and Minh Pham have exposed multiple critical vulnerabilities in the Rack...

SAP NetWeaver 0-Day Flaw Actively Exploited to Deploy Webshells

SAP disclosed a critical zero-day vulnerability, identified as CVE-2025-31324, in its NetWeaver Visual Composer component. This...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Advanced Multi-Stage Carding Attack Hits Magento Site Using Fake GIFs and Reverse Proxy Malware

A multi-stage carding attack has been uncovered targeting a Magento eCommerce website running an...

Hannibal Stealer: Cracked Variant of Sharp and TX Malware Targets Browsers, Wallets, and FTP Clients

A new cyber threat, dubbed Hannibal Stealer, has surfaced as a rebranded and cracked...

Rack Ruby Framework Vulnerabilities Let Attackers Inject and Manipulate Log Content

Researchers Thai Do and Minh Pham have exposed multiple critical vulnerabilities in the Rack...