Tactics Tie Ransom Cartel Group to Defunct REvil RansomwareTactics Tie Ransom Cartel Group to Defunct REvil Ransomware
Ransom Cartel ransomware-as-a-service operator blog claims to offer a new and improved version of REvil ransomware.
![Image of a laptop with police tape around it, signifying a cybercrime attack Image of a laptop with police tape around it, signifying a cybercrime attack](https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt7eb95dd06a000c1e/64f15549edca01c7397e2c5d/ransomware_Andreas_Prott_Alamy_.jpeg?width=1280&auto=webp&quality=95&format=jpg&disable=upscale)
Although the REvil ransomware-as-a-service operation appeared to evaporate last October, analysts have found the group's influence is still considerable.
Notably, threat researchers from Unit 42 reported finding connections between REvil activities and that of ransomware group Ransom Cartel, an up-and-coming cybercrime group claiming to offer "the same, yet improved software" as REvil.
Following analysis, the Unit 42 team determined Ransom Cartel somehow was able to gain access to REvil ransomware source code. Ransom Cartel also mimics REvil tactics, including double extortion, Unit 42 added. However, the researchers said there are some aspects of the REvil operation that Ransom Cartel seems to lack.
"Based on the fact that the Ransom Cartel operators clearly have access to the original REvil ransomware source code, yet likely do not possess the obfuscation engine used to encrypt strings and hide API calls," the Unit 42 ransomware report explained, "we speculate that the operators of Ransom Cartel had a relationship with the REvil group at one point, before starting their own operation."
About the Author
You May Also Like
Uncovering Threats to Your Mainframe & How to Keep Host Access Secure
Feb 13, 2025Securing the Remote Workforce
Feb 20, 2025Emerging Technologies and Their Impact on CISO Strategies
Feb 25, 2025How CISOs Navigate the Regulatory and Compliance Maze
Feb 26, 2025Where Does Outsourcing Make Sense for Your Organization?
Feb 27, 2025