
The operators of REvil ransomware (also known as Sodinokibi) have breached Brazilian electricity company Light SA and are demanding a ransom of $14 million!
The company spoke to a local newspaper, where it confirmed the attack.
Light SA admitted to the attack, but did not provide many details about the ransomware and the breach. It said, simply, that the attackers used malware that encrypted Windows systems.
AppGate researchers have analyzed a sample of the malware and linked it to the REvil ransomware.
“Our team had access to the binary likely used in the attack and we were able to confirm that the sample comes from the known REvi l (or Sodinokibi) ransomware,” the analysis published by AppGate states. “While we cannot confirm that this was the exact same file used in the attack, evidence suggests that it is linked to the Light SA breach .”
The binary was uploaded to a public sandbox, suggesting that company personnel are trying to determine the nature of the file.
The malware's "behavior" is similar to that of other binaries that researchers have identified in this ransomware "family.".

Researchers analyzed the ransomware and were able to see some evidence.
The ransom payment page is hosted on the Tor network . The hackers demanded 106,870.19 XMR (Monero) from the electricity company Light SA by June 19. The deadline passed and the Sodinokibi ransomware operators doubled the amount (215,882.8 XMR) . So the company has to pay about $14 million.
The payment page includes information about the attackers. From there, it is confirmed that the REvil ransomware gang is responsible for the attack
“The whole attack looks very professional. The page even includes chat support, where the victim can talk directly to the attacker. REvil operates as a RaaS (Ransomware as a Service) and the group behind the operation appears to be connected to “Pinchy Spider”, which is also behind the GandCrab ransomware,” the researchers said.
“During the attack, we noticed that the site was offline and displaying a database error message ,which could be related to the attack.”
