REvil ransomware group’s infrastructure comes back online hinting at fresh campaign

Connor Jones reports:

….. Some researchers noted the return of REvil’s ‘happy blog’ – the place where it announced its hacks – on 19 April, returning an Nginx 404 error. Others said the signs of a return started as far back as December, one month after law enforcement made the original arrests of the gang members.

Using the TOR onion address used for REvil’s original happy blog, prospective visitors are now redirected to a new website where there are currently 26 pages filled with details of the group’s successful hacks, largely old hacks previously claimed by REvil.

Read more at ITPro.

 

About the author: Dissent

Comments are closed.