The REvil ransomware group is back in operation with new infrastructure and a modified encryptor after supposedly being shut down last year.

See also: REvil ransomware member extradited to US to stand trial for Kaseya attack
In October 2021, the notorious ransomware gang was shut down after a law enforcement operation took down its Tor servers. This was followed by the arrest of several of its key members by Russia's FSB.
As Russia’s invasion of Ukraine soured relations between the US and Russia, the US government went ahead and unilaterally closed its cybersecurity communication channel with Moscow. As a result, the US has also withdrawn from the REvil negotiation process
See also: Russia: Charges 8 gang members suspected of REvil ransomware
While it briefly appeared that the REvil operation had closed up shop for good, the group's old Tor infrastructure recently started working again. However, instead of displaying old websites, Tor servers are redirecting visitors to URLs for a new anonymous ransomware operation, according to a report from BleepingComputer.
A new REvil encryptor
Websites are constantly being redirected, so finding a new sample of REvil's ransomware encryptor and analyzing it is the only way to tell whether the group has indeed returned or not.
Fortunately, Avast ’s Director of Malware Research , Jakub Kroustek, recently found a sample of the encryptor used by the new ransomware group that may or may not be REvil. It’s worth noting that other ransomware operations have used REvil’s encryptor in the past, but all of them used patched executables as opposed to directly accessing the group ’s source code .
Multiple security researchers and malware analysts who spoke to BleepingComputer confirmed that this new sample is built from the REvil source code, although it includes some new changes. In a post on Twitter, security researcher R3MRUM said that although the sample's version number is 1.0, it is actually a continuation of the last REvil encryptor version (2.08) released before the team was shut down.

Intel's advanced general manager Vitali Kremez was able to analyze the sample in question and confirmed to BleepingComputer that it had been compiled from source code on April 26th and had not been patched.
Although REvil's original public spokesperson, known as "Unknown," remains missing, threat intelligence researcher FellowSecurity told the news outlet that one of the ransomware group's original core developers had restarted the operation under a new name.
See also: FBI: Seizes $2.3 million from REvil, Gandcrab ransomware affiliates
At this time, we don't yet know what this renewed version of the REvil ransomware group is referring to, but now that REvil is back, expect to see more high-profile attacks on important and valuable targets worldwide.
Information source: techradar.com
