Four members of the notorious REvil ransomware group were released by Russian authorities in January 2022 after serving their sentences while awaiting trial. Andrey Bessonov, Mikhail Golovachuk, Roman Muromsky, and Dmitry Korotayev pleaded guilty to carding and malware distribution charges related to their involvement in REvil operations from October 2015 to January 2022.
## Court Sentences and Release
The Russian court sentenced all four defendants to five years in prison but immediately released them, crediting time already served in detention during the investigation and trial process. These four were part of a larger group of eight REvil members arrested by Russian authorities.
The remaining four members—Artem Zayets, Alexey Malozemov, Daniil Puzyrevsky, and Ruslan Khansvyarov—received harsher sentences after refusing to plead guilty. Their prison terms ranged from 4.5 to 6 years, with Puzyrevsky receiving the longest sentence of 6 years for additional malware distribution charges.
## REvil’s Rise and Fall
REvil ransomware emerged in April 2019 as the successor to GandCrab and quickly became one of the most dangerous ransomware operations. The group earned over $100 million within its first year by targeting businesses with high ransom demands.
The turning point came in July 2021 when REvil executed a devastating supply chain attack through Kaseya, affecting over 1,500 businesses worldwide. This attack prompted direct diplomatic intervention, with President Biden calling on President Putin to address Russian-based cybercriminals.
## International Law Enforcement Response
The Kaseya attack triggered a coordinated international response:
– **November 2021**: U.S. authorities arrested Ukrainian national Yaroslav Vasinskyi, responsible for the Kaseya attack
– **May 2024**: Vasinskyi was sentenced to 13 years in prison and ordered to pay $16 million in restitution
– **Ongoing seizures**: Authorities seized over $6 million from Russian national Yevgeniy Polyanin, linked to at least 3,000 ransomware attacks
## The Final Takedown
After the Kaseya incident, REvil temporarily suspended operations but resumed two months later. However, law enforcement had already infiltrated their infrastructure during the pause. When REvil restored their systems, they unknowingly reactivated machines controlled by authorities.
This led to the Russian Federal Security Service (FSB) arresting 14 suspects in January 2022, effectively dismantling the entire REvil operation. The FSB claimed to have identified all gang members and neutralized their criminal infrastructure.
## Diplomatic Complications
The cooperation between U.S. and Russian authorities on cybersecurity matters deteriorated following Russia’s invasion of Ukraine. In April 2022, Russia announced that the United States had unilaterally terminated cybersecurity communication channels and withdrawn from negotiations regarding the REvil case.
The REvil takedown represents one of the most significant victories against ransomware operations, demonstrating both the potential for international cooperation in cybersecurity and the challenges posed by geopolitical tensions.
