{"id":45147,"date":"2026-04-06T17:24:13","date_gmt":"2026-04-06T09:24:13","guid":{"rendered":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/2026\/04\/06\/bka-identifies-revil-leaders-behind-130-german-ransomware-attacks\/"},"modified":"2026-04-06T17:24:13","modified_gmt":"2026-04-06T09:24:13","slug":"bka-identifies-revil-leaders-behind-130-german-ransomware-attacks","status":"publish","type":"post","link":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/2026\/04\/06\/bka-identifies-revil-leaders-behind-130-german-ransomware-attacks\/","title":{"rendered":"BKA Identifies REvil Leaders Behind 130 German Ransomware Attacks"},"content":{"rendered":"<div style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgsBHK8DX9E30isZVcn1e-a6p8bmNUAki0SmUh1Tkt9dP8L3D4_WcwT64CI5OVuh1brb1Z4pff7onp90K76ktHbs6-H6Kr0rq9Q2f03oW91e3mA5dN5XdLDyWNns5NcfXw7BKFzH28SbpaFo9l8TmMeZ7Mt6o1ePanKeFYGa8V1S9Rez_E30SIAx2yvfuNl\/s1600\/revil-ransomware.jpg\" style=\"display: block; padding: 1em 0; text-align: center; clear: left; float: left;\"><img decoding=\"async\" border=\"0\" data-original-height=\"470\" data-original-width=\"900\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgsBHK8DX9E30isZVcn1e-a6p8bmNUAki0SmUh1Tkt9dP8L3D4_WcwT64CI5OVuh1brb1Z4pff7onp90K76ktHbs6-H6Kr0rq9Q2f03oW91e3mA5dN5XdLDyWNns5NcfXw7BKFzH28SbpaFo9l8TmMeZ7Mt6o1ePanKeFYGa8V1S9Rez_E30SIAx2yvfuNl\/s1600\/revil-ransomware.jpg\" alt=\"BKA Identifies REvil Leaders Behind 130 German Ransomware Attacks\"\/><\/a><\/div>\n<p>Germany&#8217;s Federal Criminal Police Office (aka BKA or the Bundeskriminalamt) has unmasked the real identity of the main threat actors associated with the now-defunct <a href=\"https:\/\/thehackernews.com\/2021\/04\/hackers-threaten-to-leak-stolen-apple.html\">REvil<\/a> (aka <b>Sodinokibi<\/b>) ransomware-as-a-service (RaaS) operation.<\/p>\n<p>The threat actor, who went by the alias <b>UNKN<\/b>, functioned as a representative of the group, advertising the ransomware in June 2019 on the XSS cybercrime forum. He&nbsp;has now been identified&nbsp;as <a href=\"https:\/\/www.bka.de\/DE\/IhreSicherheit\/Fahndungen\/Personen\/BekanntePersonen\/CC_BW\/DMS\/Sachverhalt.html\">Daniil Maksimovich&nbsp;Shchukin<\/a>, a 31-year-old Russian national. He&nbsp;also went by the online monikers Oneiilk2, Oneillk2, Oneillk22, and&nbsp;GandCrab.<\/p>\n<p>The development&nbsp;was <a href=\"https:\/\/krebsonsecurity.com\/2026\/04\/germany-doxes-unkn-head-of-ru-ransomware-gangs-revil-gandcrab\/\">reported<\/a> by independent security journalist Brian&nbsp;Krebs.<\/p>\n<p>&#8220;From early 2019 at the latest until at least July 2021, the wanted person, in cooperation with other individuals, acted as the leader of one of the largest global ransomware groups, known as GandCrab\/REvil,&#8221; BKA said. &#8220;The perpetrators demanded large ransom payments in exchange for decrypting and not leaking&nbsp;data.&#8221;<\/p>\n<p>Also added to the wanted list&nbsp;is <a href=\"https:\/\/www.bka.de\/DE\/IhreSicherheit\/Fahndungen\/Personen\/BekanntePersonen\/CC_BW\/ASK\/Sachverhalt.html\">Anatoly Sergeevitsch&nbsp;Kravchuk<\/a>, a 43-year-old Russian born in the Ukrainian city of Makiivka. He&nbsp;is alleged to have acted as the developer of REvil during the same time&nbsp;period.<\/p>\n<p>Shchukin and Kravchuk are suspected of having carried out 130 ransomware attacks across Germany. Out&nbsp;of these, 25 cases led to the payment of &#8364;1.9&nbsp;million ($2.19&nbsp;million). The&nbsp;incidents collectively incurred financial damages exceeding &#8364;35.4&nbsp;million ($40.8&nbsp;million).<\/p>\n<p><a href=\"https:\/\/unit42.paloaltonetworks.com\/revil-threat-actors\/\">REvil<\/a> (aka Water Mare and Gold Southfield) was one of&nbsp;the <a href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/security\/news\/ransomware-spotlight\/ransomware-spotlight-revil\">prolific ransomware&nbsp;groups<\/a> that counted companies like JBS and Kaseya among its victims. An&nbsp;evolution of&nbsp;the <a href=\"https:\/\/www.trellix.com\/blogs\/research\/dismantling-a-prolific-cybercriminal-empire\/\">GandCrab<\/a> ransomware, the e-crime&nbsp;crew <a href=\"https:\/\/thehackernews.com\/2021\/07\/revil-ransomware-gang-mysteriously.html\">mysteriously went&nbsp;offline<\/a> in mid-July 2021, only to resurface in two months&nbsp;later.<\/p>\n<p>By October 2021, the&nbsp;group <a href=\"https:\/\/thehackernews.com\/2021\/10\/revil-ransomware-gang-goes-underground.html\">ceased operations<\/a>, and its data leak site became inaccessible as part of&nbsp;a <a href=\"https:\/\/thehackernews.com\/2021\/10\/feds-reportedly-hacked-revil-ransomware.html\">law enforcement&nbsp;operation<\/a>. Weeks&nbsp;later, Romanian law enforcement authorities <a href=\"https:\/\/thehackernews.com\/2021\/11\/suspected-revil-ransomware-affiliates.html\">announced<\/a> the arrest of two individuals for their roles as affiliates of the REvil ransomware&nbsp;family.<\/p>\n<p>In a rare move, Russia&#8217;s Federal Security Service&nbsp;(FSB) <a href=\"https:\/\/thehackernews.com\/2022\/01\/russia-arrests-revil-ransomware-gang.html\">disclosed<\/a> in January 2022 that it had arrested several members belonging to the notorious REvil ransomware gang and neutralized its operations. Four&nbsp;of those members&nbsp;were <a href=\"https:\/\/thehackernews.com\/2024\/10\/four-revil-ransomware-members-sentenced.html\">sent to several years in&nbsp;prison<\/a> in October 2024, Russian news publication Kommersant&nbsp;reported.<\/p>\n<p>UNKN&nbsp;also <a href=\"https:\/\/www.kelacyber.com\/blog\/will-the-revil-story-finally-be-over\/\">disappeared<\/a> from the cybercrime forums coinciding with the operation, prompting another user, REvil (later renamed to 0_neday), to become the public face of the gang&#8217;s operations.<\/p>\n<p>In&nbsp;an <a href=\"https:\/\/therecord.media\/i-scrounged-through-the-trash-heaps-now-im-a-millionaire-an-interview-with-revils-unknown\">interview<\/a> with Recorded Future&#8217;s Dmitry Smilyanets in March 2021, UNKN said he had been in the ransomware business since 2007 and that they had as many as 60 affiliates working for the group at one&nbsp;point.<\/p>\n<p>&#8220;As a child, I scrounged through the trash heaps and smoked cigarette butts. I&nbsp;walked 10 km one way to the school,&#8221; he was quoted as saying. &#8220;I wore the same clothes for six months. In&nbsp;my youth, in a communal apartment, I didn&#8217;t eat for two or even three days. Now&nbsp;I am a millionaire.&#8221;<\/p>\n<div><\/div>\n<div>Found this article interesting?  Follow us on <a href='https:\/\/news.google.com\/publications\/CAAqLQgKIidDQklTRndnTWFoTUtFWFJvWldoaFkydGxjbTVsZDNNdVkyOXRLQUFQAQ' rel='noopener' target='_blank'>Google News<\/a>, <a href='https:\/\/twitter.com\/thehackersnews' rel='noopener' target='_blank'>Twitter<\/a> and <a href='https:\/\/www.linkedin.com\/company\/thehackernews\/' rel='noopener' target='_blank'>LinkedIn<\/a> to read more exclusive content we post.<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Germany&#8217;s Federal Criminal Police Office (aka BKA or the Bundeskriminalamt) has unmasked the real identity of the main threat actors associated with the now-defunct REvil (aka Sodinokibi) ransomware-as-a-service (RaaS) operation.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[],"class_list":["post-45147","post","type-post","status-publish","format-standard","hentry","category-thehackernews"],"_links":{"self":[{"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/posts\/45147","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/comments?post=45147"}],"version-history":[{"count":0,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/posts\/45147\/revisions"}],"wp:attachment":[{"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/media?parent=45147"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/categories?post=45147"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/tags?post=45147"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}