Cybercriminals are realizing that the operators of the REvil ransomware may have hijacked ransom negotiations to cut off payments from their partners.

See also: Marketron: BlackMatter ransomware targeted software provider
Using a cryptographic scheme that allowed them to decrypt any system locked by REvil ransomware, the operators left their partners out of the deal and stole the entire ransom amount.
Conversations about this practice began a while ago in underground forums, in posts by gang associates, and were recently confirmed by security researchers and malware developers.
The REvil ransomware, also known as Sodinokibi, appeared in the first half of 2019 and made its reputation as the successor to the GandCrab ransomware-as-a-service (RaaS) operation.
The RaaS business model for cybercriminal activities involves a developer, who creates the malware and builds the infrastructure, and partners who are hired to hack and encrypt victims. The processes are divided between the two parties with the partners taking the largest share (typically 70-80%).
See also: BlackMatter ransomware: Demands 5.9 million from agricultural cooperative
The REvil gang developed a highly lucrative private business that only accepted highly experienced hackers.
Although the REvil operation began as an “honest” cybercrime group, it soon shifted to defrauding its partners.
Yelisey Boguslavskiy, head of Advanced Intel, told BleepingComputer that since at least 2020, various hackers on underground forums have claimed that RaaS initiated negotiations with victims in secret chats, without the knowledge of their partners.
Boguslavskiy says that REvil administrators have opened a second chat, identical to the one their associates used to negotiate the ransom with the victim.
When the conversations reached a critical point, the REvil group would go to the original conversation, hack it, and, posing as the victim, tell the partners that they were stopping negotiations and did not want to pay the ransom, Boguslavskiy explained.
See also: Windows MSHTML bug: Ransomware groups exploit the flaw
Then, in the second conversation, Revil's administrators continued discussions with the victim and once they agreed, they took the entire ransom without giving the partners their share.
Information source: bleepingcomputer.com
