The FBI seized $2.3 million in August from a known affiliate of REvil and the GandCrab ransomware.

See also: REvil ransomware: “Shuts down” again after breaching Tor sites
The agency seized 39.89138522 bitcoins worth approximately $2.3 million at current prices from an Exodus wallet on August 3, 2021.
Exodus is a desktop or mobile wallet that owners can use to store cryptocurrencies, including Bitcoin, Ethereum, Solana, and many others.
The FBI did not reveal how they gained access to the wallet, other than that it was now in their hands, indicating that they likely gained access to the wallet's private key or password.
“The United States of America files this verified material complaint against 39.89138522 Bitcoin seized from Exodus Wallet, now in the custody and management of the Federal Bureau of Investigation (“FBI”) Dallas Division, One Justice Way, Dallas Texas,” the complaint .
The complaint goes on to say that the wallet contained REvil ransom payments belonging to an affiliate identified as “Aleksandr Sikerin, a/k/a Alexander Sikerin, a/k/a Oleksandr Sikerin” with an email address of “engfog1337@gmail.com.”
See also: FBI: Warns of brand phishing targeting high-profile customers
While the FBI does not indicate the online alias of the malicious actor, the name “engfog” in the email address is linked to a known affiliate of GandCrab and REvil/Sodinokibi known as “Lalartu.”
The GandCrab and REvil organizations operated as Ransomware-as-a-Service (RaaS), where the key operators collaborate with third-party hackers, known as collaborators.
As part of this agreement, the main operators develop and manage the encryption/decryption software, payment gateway and data leakage sites. The subsidiaries are tasked with hacking corporate networks, stealing data and developing ransomware to encrypt devices.

Any ransom payments will then be split between the affiliates and the main operators, with the operators generally earning 20-30% of the ransom and the affiliates making the rest.
As part of his investigation, security researcher Alon Gal tracked Lalartu under the alias “Engfog” or “Eng_Fog,” which matches the email address “engfog1337@gmail.com” listed in the FBI complaint.
In November, the Department of Justice announced that the FBI had seized $6 million in ransom money paid to the REvil ransomware gang.
It is unclear whether this $2.3 million is part of the previously announced figure or additional ransom money seized by the FBI.
See also: USA: $10 million reward for REvil leaders
Law enforcement's ongoing strategy to disrupt the financial and subsidiary systems of ransomware operations is paying off.
This activity has led to numerous arrests and the dismantling of infrastructure, such as:
- The disruption of Netwalker's ransomware operation and the arrest of a subsidiary in Canada.
- The arrest of the two members of the Egregor operation led to the closure of the organization.
- The arrest of 12 people believed to be linked to ransomware attacks against 1,800 victims in 71 countries.
- The arrest of a Ukrainian national believed to be behind the Kaseya ransomware attack.
Arrests and infrastructure seizures are scaring ransomware gangs into shutting down their operations, including REvil in October and BlackMatter in July.
