The dark web servers for the operation of the REvil ransomware were suddenly activated after almost two months of inactivity. It is unclear whether this signals the return of the ransomware gang or if the servers are being activated by law enforcement authorities.
On July 2, the REvil ransomware gang, also known as Sodinokibi, exploited a zero‑day vulnerability in the Kaseya VSA remote‑management software to encrypt about 60 managed service providers (MSPs) and over 1,500 of their business customers.

See also: Ransomware gang: We will leak your data if you contact the FBI
Subsequently, the REvil operation demanded 5 million dollars from MSP for decryption or 44,999 dollars for each encrypted extension in individual businesses.
The gang also demanded 70 million dollars for a master decryption key to decrypt all Kaseya victims, but soon dropped the price to 50 million dollars.
After the attack, the ransomware gang faced increasing pressure from law enforcement and the White House, who warned that the US would take action themselves if Russia does not act against the threatening actors located within its country.
See also: Ransomware gangs: What criteria do they use to choose target companies?
A short while later, the ransomware gang REvil disappeared and all Tor servers and their infrastructure were shut down.
To date, it is not clear what happened, but it left ransomware victims who wanted to negotiate unable to do so and without the ability to restore files.
Mysteriously, Kaseya later obtained the main decryption key for the attack's victims and stated that it came from a trusted third party. It is believed that Russian intelligence services obtained the decryption key from the threatening actors and handed it over to the FBI as a goodwill gesture.
The REvil infrastructure is suddenly activated
Today, both the Tor payment/trading site and the REvil data leak site resurfaced online.
The most recent victim on the REvil data leak site was added on July 8, 2021, just five days before REvil's mysterious disappearance.
See also: Ransomware attacks: 288% increase in the first half of 2021
In contrast to the data leak site, which is operational, the Tor negotiation site does not appear to be fully functional yet. While it displays the login screen, as shown below, it does not allow victims to connect to the site.

The gang's https://decoder.re/ is still offline at this time.
It is not currently clear whether the ransomware gang is back in operation, whether the servers have been reactivated by accident, or if it is due to the actions of law enforcement.
Information source: bleepingcomputer.com
