Originally published 06/06/2022
A recent denial-of-service (DDoS) campaign against a hospitality customer of Akamai, a cloud networking provider, saw the defunct REvil ransomware gang claim responsibility. It should be noted that researchers believe there is a high probability that the attack is not a resurgence of the infamous cybercriminal group but rather a copycat operation.
Akamai researchers have been monitoring the DDoS attack since May 12th, when a customer alerted the company’s Security Incident Response Team (SIRT) of an attempted attack by a group purporting to be REvil. The requests contain demands for payment, a bitcoin wallet, and business/political demands.[1] While the attackers claim to be REvil, it is unclear whether the defunct group is responsible for the attacks, given that they appear smaller than previous attacks the group claimed responsibility for. The apparent political motivation behind the DDoS campaign is also inconsistent with REvil’s M.O.
REvil, which hasn’t been seen since July 2021, was a Russia-based ransomware-as-a-service (RaaS) group well-known for its attacks against Kaseya, JBS Foods, and Apple.[2] The disruptive nature of their attacks prompted international authorities to take action against the group, with Europol arresting several cybercriminals in November 2021.[2] In March 2022, Russia, which, up until then, had done little to stop REvil’s operations, claimed responsibility for fully toppling the group at the behest of the U.S. government, arresting its individual members. One person arrested was instrumental in helping the ransomware group DarkSide, the group responsible for the Colonial Pipeline attack in May of 2021.[2]
The recent DDoS attack, which would be a shift in strategy for REvil, consisted of an HTTP GET request whose path included a 554-byte message demanding payment. The victim was directed to send the bitcoin payment to a wallet address that “currently has no history and is not tied to any previously known bitcoin.”[2] The attack also includes a geo-specific demand that requires the targeted company to cease business operations across an entire country. The attackers threatened to launch follow-up attacks that would disrupt global business operations if the demand was not met and the ransom was not paid within a specified timeframe.[2]
There is a precedent for REvil using DDoS in its previous attacks, but it does not appear that this attack is the work of REvil. REvil’s M.O. was to gain access to a target network or organization and either encrypt or steal sensitive data, demanding payment to decrypt it or prevent information leakage to the highest bidders, or threatening public disclosure of sensitive or damaging information. The technique in this attack is different from their normal strategy. The political motivation tied to the attack, which is linked to a legal ruling about the targeted company’s business model, also goes against REvil’s normal tactics, with leaders in the past saying that they were purely profit-driven.[2] However, it is possible that REvil is seeking a resurgence by trying out a new business model of DDoS extortion. However, it is more likely that cybercriminals use the name of a notorious cybercriminal group to intimidate the targeted organization into meeting their demands.[2]
Because the HTTP GET request headers are out of order relative to “typical” patterns, a custom-developed DDoS attack tool is assumed to be used, and the values may change between campaigns. As such, Larry Cashdollar, a researcher at Akamai, says that writing signatures for these patterns may not benefit defenders from an IOC standpoint. More information can be found at the link below:
https://www.akamai.com/blog/security/revil-resurgence-or-copycat
(1) Cashdollar, Larry. “REvil Resurgence? Or a Copycat?” Akamai Blog. Akamai Technologies, May 25, 2022. https://www.akamai.com/blog/security/revil-resurgence-or-copycat.
(2) Montalbano, Elizabeth. “Cybergang Claims Revil Is Back, Executes DDoS Attacks.” Threatpost English Global, May 26, 2022. https://threatpost.com/cybergang-claims-revil-is-back-executes-ddos-attacks/179734/.
Contributing Security Analysts: Dorian Pope, Sreten Dedic, EJ Bulut, Uday Bilakhiya, Tural Hagverdiyev.