{
	"id": "bad572ea-d86d-4031-895f-375f705b76ca",
	"created_at": "2026-04-06T00:14:57.880794Z",
	"updated_at": "2026-04-10T13:12:43.720966Z",
	"deleted_at": null,
	"sha1_hash": "f6507232584e747b8db58c4f98189abc66dee7b4",
	"title": "REvil ransomware affiliates arrested in Romania and Kuwait",
	"llm_title": "",
	"authors": "",
	"file_creation_date": "0001-01-01T00:00:00Z",
	"file_modification_date": "0001-01-01T00:00:00Z",
	"file_size": 2076251,
	"plain_text": "REvil ransomware affiliates arrested in Romania and Kuwait\r\nBy Sergiu Gatlan\r\nPublished: 2021-11-08 · Archived: 2026-04-05 14:55:21 UTC\r\nRomanian law enforcement authorities have arrested two suspects believed to be Sodinokibi/REvil ransomware affiliates on\r\nNovember 4, both of them allegedly responsible for infecting thousands of victims.\r\nDIICOT (the Romanian Directorate for Investigating Organized Crime and Terrorism) and judicial police officers carried out\r\nfour home searches in Constanța, seizing mobile devices (laptops, mobile phones) and storage media.\r\nThe Bucharest Tribunal also ordered the pre-trial detention for the two REvil affiliates for 30 days.\r\nhttps://www.bleepingcomputer.com/news/security/revil-ransomware-affiliates-arrested-in-romania-and-kuwait/\r\nPage 1 of 4\n\n0:00\r\nhttps://www.bleepingcomputer.com/news/security/revil-ransomware-affiliates-arrested-in-romania-and-kuwait/\r\nPage 2 of 4\n\nVisit Advertiser websiteGO TO PAGE\r\nOn the same day, Kuwaiti authorities also arrested a GandGrab ransomware affiliate, the three of them being suspected of\r\nroughly 7,000 attacks and of asking more than €200 million in ransoms.\r\nIn total, together with the ones apprehended on November 4, authorities arrested seven suspects linked to REvil and\r\nGandGrab since February 2021.\r\nThree other individuals believed to be REvil affiliates were apprehended in South Korea in February, April, and October,\r\nand one was arrested in Europe last month.\r\nThe announcement, made today by Europol (the European Union Agency for Law Enforcement Cooperation), says the\r\narrests are the result of operation GoldDust, which involved law enforcement agents from 17 countries, the Europol,\r\nEurojust, and the INTERPOL.\r\n\"Since 2018, Europol has supported a Romanian-led investigation which targets the GandCrab ransomware family and\r\ninvolved law enforcement authorities from a number of countries, including the United Kingdom and the United States,\" the\r\nEuropol said.\r\n\"All these arrests follow the joint international law enforcement efforts of identification, wiretapping and seizure of some of\r\nthe infrastructure used by Sodinokibi/REvil ransomware family, which is seen as the successor of GandCrab.\"\r\nThese recent arrests show that law enforcement worldwide has realized that they can't get to the core ransomware gang\r\noperators who are safe in Russia.\r\nHowever, their Ransomware-as-a-Service (RaaS) operations can easily be disrupted by arresting ransomware\r\naffiliates located all over the world.\r\nUS Deputy Attorney General Lisa Monaco also announced that the US will crack down on ransomware activity in an\r\ninterview with the Associated Press on November 4.\r\nhttps://www.bleepingcomputer.com/news/security/revil-ransomware-affiliates-arrested-in-romania-and-kuwait/\r\nPage 3 of 4\n\nAutomated Pentesting Covers Only 1 of 6 Surfaces.\r\nAutomated pentesting proves the path exists. BAS proves whether your controls stop it. Most teams run one without the\r\nother.\r\nThis whitepaper maps six validation surfaces, shows where coverage ends, and provides practitioners with three diagnostic\r\nquestions for any tool evaluation.\r\nSource: https://www.bleepingcomputer.com/news/security/revil-ransomware-affiliates-arrested-in-romania-and-kuwait/\r\nhttps://www.bleepingcomputer.com/news/security/revil-ransomware-affiliates-arrested-in-romania-and-kuwait/\r\nPage 4 of 4",
	"extraction_quality": 1,
	"language": "EN",
	"sources": [
		"ETDA"
	],
	"origins": [
		"web"
	],
	"references": [
		"https://www.bleepingcomputer.com/news/security/revil-ransomware-affiliates-arrested-in-romania-and-kuwait/"
	],
	"report_names": [
		"revil-ransomware-affiliates-arrested-in-romania-and-kuwait"
	],
	"threat_actors": [],
	"ts_created_at": 1775434497,
	"ts_updated_at": 1775826763,
	"ts_creation_date": 0,
	"ts_modification_date": 0,
	"files": {
		"pdf": "https://archive.orkl.eu/f6507232584e747b8db58c4f98189abc66dee7b4.pdf",
		"text": "https://archive.orkl.eu/f6507232584e747b8db58c4f98189abc66dee7b4.txt",
		"img": "https://archive.orkl.eu/f6507232584e747b8db58c4f98189abc66dee7b4.jpg"
	}
}