Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Software/S0496
MITRE ATT&CK Malware

REvil (S0496)

SodinSodinokibi
ShareXLinkedInRedditHN

[REvil](https://attack.mitre.org/software/S0496) is a ransomware family that has been linked to the [GOLD SOUTHFIELD](https://attack.mitre.org/groups/G0115) group and operated as ransomware-as-a-service (RaaS) since at least April 2019. [REvil](https://attack.mitre.org/software/S0496), which as been used against organizations in the manufacturing, transportation, and electric sectors, is highly configurable and shares code similarities with the GandCrab RaaS.(Citation: Secureworks REvil September 2019)(Citation: Intel 471 REvil March 2020)(Citation: Group IB Ransomware May 2020)

Platforms: Windows

▪Techniques implemented (43)

T1486Data Encrypted for ImpactT1059.003Windows Command ShellT1059.001PowerShellT1573.002Asymmetric CryptographyT1055Process InjectionT1036.005Match Legitimate Resource Name or LocationT1112Modify RegistryT1485Data DestructionT1012Query RegistryT1059.005Visual BasicT1041Exfiltration Over C2 ChannelT1489Service StopT1082System Information DiscoveryT1106Native APIT1204.002Malicious FileT1134.002Create Process with TokenT1685Disable or Modify ToolsT1480.002Mutual ExclusionT1083File and Directory DiscoveryT1027.013Encrypted/Encoded FileT1189Drive-by CompromiseT1007System Service DiscoveryT1047Windows Management InstrumentationT1140Deobfuscate/Decode Files or InformationT1566.001Spearphishing AttachmentT1105Ingress Tool TransferT1688Safe Mode BootT1680Local Storage DiscoveryT1614.001System Language DiscoveryT1134.001Token Impersonation/TheftT1071.001Web ProtocolsT1069.002Domain GroupsT1070.004File DeletionT1490Inhibit System RecoveryT1027.011Fileless StorageT0863User ExecutionT0881Service StopT0849MasqueradingT0882Theft of Operational InformationT0828Loss of Productivity and RevenueT0869Standard Application Layer ProtocolT0886Remote ServicesT0853Scripting

▪Used by groups (2)

G0046FIN7G0115GOLD SOUTHFIELD
S0496on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.