
REvil ransomware, also known as Sodinokibi, was widely observed in late April 2019. REvil ransomware is part of Ransomware-as-a-Service (RaaS), in which a group of individuals maintains the source code, while other affiliated groups distribute the ransomware. Many researchers believe that REvil ransomware is similar to GandCrab ransomware, since with the appearance of REvil ransomware, the activity of GandCrab ransomware has decreased to a large extent, while they have the same codes. The hackers behind the development and maintenance of this malware have released a new version of this ransomware, REvil ransomware 2.2. This new version of the ransomware uses the Windows Restart Manager API, aiming to terminate processes that open the file that has been targeted for encryption. This is because if the file is opened by a specific process, then another process on the same file will be terminated by the Windows. Malware have found that Sodinokibi ransomware has now implemented this technique, using the Windows Restart Manager. The Windows Restart Manager is also used by other ransomware, such as SamSam and LockerGoga. In addition, REVIL ransomware opens files for encryption without sharing (dwShareMode equals 0). This results in the Restart Manager being notified every time an attempt to open an already open file is detected. In addition, the hackers added a command-line option, which is “silent” and skips blacklisted processes and services as well as deleting shadow copies.

Popular analyst Vitali Kremez noted that REvil Decryptor v2.2 also uses the Windows Restart Manager API to terminate any process that is decrypting files. Finally, with the new features that have now been added, REvil Ransomware 2.2 can encrypt some extremely critical files.
