Back to Resources

SentinelOne Vs. REvil Ransomware – Protect Mode

The latest media reports suggest that the REvil ransomware family is behind the recent attack on JBS. The ransomware attack affected operations in North America and Australia, igniting fears of product shortages and price increases. The REvil group has been in operation (in current form) since mid 2019. Their ransomware is distributed via multiple methods including Exploit Kits, exploitation, as well as partnerships with other malware ‘frameworks’.
The SentinelOne Endpoint Protection Platform is capable of preventing & detecting REvil and all related, malicious, artifacts. Since launch, REvil has been available through multiple ‘underground forums’. There is some evidence to support ties between REvil / the REvil Gang and Ukraine and Russian actors. There are also indications that they work with other ransomware groups, and may have even based some of their code on GandCrab.

#ransomware #REvil #cybersecurity #infosec #endpointprotection

지금 읽기

세계에서 가장 앞선 사이버 보안 플랫폼 경험하기

지능적인 자율형 사이버 보안 플랫폼이 현재와 미래의 조직을 어떻게 보호할 수 있는지 알아보세요.