Sodinokibi, the ransomware, uses an older zero-day Windows flaw to gain admin access on compromised hosts. The flaw, codenamed CVE-2018-8453, was patched in the October 2018 Windows Update . However, it was previously exploited in August 2018 by a group of hackers known as FruityArmor.

Research has been conducted on Sodinokibi, the results of which are being studied. An interesting finding was the discovery of a “skeleton key” in the ransomware code, which acts as a backdoor in the encryption process . This allows its creator to decrypt any file, regardless of the original public and private encryption keys used to protect the victim’s data. We therefore conclude that Sodinokibi is distributed via a RaaS (ransomware-as-a-service) scheme.
GandCrab , the ransomware that predated Sodinokibi and appears to be paving the way for it, was at work throughout 2018 and 2019. In June, it officially shut down, leaving Sodin to flourish as its successor .

Many, in fact, claim that the two ransomware come from the same developers. Which could be true, as, on the one hand, there are similarities in the two codes, and on the other hand, when Sodinokibi was in its early stages, its attacks were assisted by GandCrab.
It is also worth mentioning that two similar attacks , but at different intervals. It also seems to be no coincidence that Sodinokibi accelerated its release processes when GandCrab was shut down.
Of course, these are all hypotheses based on certain clues. For now, there is no guaranteed connection between the two ransomware strains.
However, the relationship between GandCrab and Sodinokibi requires more and more comprehensive research if we want to be accurate in our assumptions. It is certainly a topic that will concern various researchers in the coming months and we expect that with the results of the research, we will gain a comprehensive view of the risk that Sodinokibi poses.
