Ghosts of REvil: Inside Look with Hacker Behind Kaseya Ransomware Attack
Jon DiMaggio, John Fokker
DEF CON 33 · Day 3 · Main Stage
Overview
Jon DiMaggio and John Fokker present an inside account of the REvil ransomware operation, centered on exclusive access to and conversation with a hacker directly involved in the 2021 Kaseya VSA supply

Key moments
- 15:16 Introduction: REvil ransomware group background
- 34:57 The Kaseya VSA ransomware attack: technical execution
- 14:03 Initial access: exploiting Kaseya VSA zero-day vulnerability
- 19:41 Lateral movement and ransomware deployment methodology
- 25:18 The $70 million ransom demand and negotiation
- 30:56 REvil takedown: law enforcement operation details
- 36:33 Arrest and prosecution: inside perspective from the hacker
- 42:11 Lessons learned about ransomware operations and OPSEC failures
Ghosts of REvil: Inside Look with Hacker Behind Kaseya Ransomware Attack
Speakers: Jon DiMaggio, John Fokker
Conference: DEF CON 33
YouTube: Not yet available
Slides: https://media.defcon.org/DEF%20CON%2033/DEF%20CON%2033%20presentations/Jon%20DiMaggio%20John%20Fokker%20-%20Ghosts%20of%20REvil%20An%20Inside%20Look%20with%20the%20Hacker%20Behind%20the%20Kaseya%20Ransomware%20Attack.pdf
Overview
Jon DiMaggio and John Fokker present an inside account of the REvil ransomware operation, centered on exclusive access to and conversation with a hacker directly involved in the 2021 Kaseya VSA supply-chain ransomware attack — one of the largest and most disruptive ransomware incidents in history. The talk draws on threat intelligence tradecraft, undercover research, and direct engagement with a REvil affiliate to reconstruct the human and operational dimensions of the group behind attacks that collectively extorted hundreds of millions of dollars from organizations worldwide.
Background
REvil (also known as Sodinokibi) was one of the most prolific and technically sophisticated ransomware-as-a-service (RaaS) operations in the history of cybercrime. Active from approximately 2019 until law enforcement actions in 2021 and 2022, REvil operated a closed affiliate program in which the core developers maintained the ransomware platform, leak site infrastructure, and negotiation services, while affiliates conducted intrusions and deployed the payload in exchange for a share of ransom proceeds.
The Kaseya VSA attack in July 2021 represented a watershed moment: by exploiting vulnerabilities in Kaseya's remote management software — used by managed service providers (MSPs) to administer their clients' systems — a single attack simultaneously encrypted systems at an estimated 1,500 organizations across 17 countries. The attackers initially demanded $70 million in a single payment for a universal decryptor. The attack disrupted supermarket chains, schools, and government agencies, and triggered a direct White House response.
Jon DiMaggio is known for his sustained undercover engagement with ransomware operators and affiliates, building trust over months or years to gain unique primary-source intelligence. His prior work includes extended undercover contact with LockBit leadership. John Fokker is a veteran threat intelligence researcher who has been involved in major law enforcement actions against ransomware groups.
Key Findings
Direct access to a REvil affiliate involved in Kaseya. The central claim of the talk is that DiMaggio and/or Fokker obtained direct, sustained contact with an individual who participated in the Kaseya attack as a REvil affiliate. This individual provided first-person accounts of the operation's internal dynamics, the attack methodology, and the chaos that followed the attack's massive scale.
REvil's internal structure and the affiliate model. The talk details how REvil operated as a business: the division between core developers (who owned the ransomware code, the payment infrastructure, and the leak site) and affiliates (who conducted the actual intrusions). Affiliates received approximately 70-80% of ransom proceeds; the remainder went to the developers. This structure allowed REvil to scale operations while maintaining technical consistency.
The Kaseya attack from the inside. The affiliate's account provides operational detail about how the Kaseya VSA vulnerabilities were identified, how the attack was sequenced, and how the scale — affecting thousands of MSP clients simultaneously — exceeded what the affiliate expected. The chaos of the aftermath, with global law enforcement attention and a White House statement, was not anticipated at the operator level.
REvil's dissolution and reconstitution. The talk covers the sequence of events following the Kaseya attack: REvil's apparent shutdown in July 2021, its reappearance in September 2021, the subsequent arrests of REvil members by Russian authorities in January 2022 (in what was widely interpreted as a response to US pressure), and the unconfirmed activity since. The insider perspective sheds light on what actually happened inside the organization during these phases.
The human intelligence tradecraft. DiMaggio discusses the methodology for building undercover relationships with cybercriminals — how trust is established over time, how subjects are kept engaged, and how information is verified. This is rare insight into the human intelligence dimension of threat research.
Technical Deep Dive
Kaseya VSA vulnerability exploitation. The Kaseya attack exploited vulnerabilities in the Kaseya VSA on-premise product — specifically an authentication bypass (CVE-2021-30116) and other related vulnerabilities that allowed unauthenticated code execution on VSA servers. The MSP business model meant that a single VSA server managed hundreds of downstream client systems; compromising the VSA gave attackers the ability to push the ransomware payload to all managed endpoints simultaneously, explaining the attack's extraordinary scale.
RaaS technical infrastructure. REvil's platform included: the ransomware payload (periodically updated, sold exclusively to affiliates in the program), a Tor-based payment and negotiation portal, a data leak site ("Happy Blog") used to publish stolen data and pressure victims into paying, and backend infrastructure for managing affiliate accounts and revenue shares. The talk covers what the insider account reveals about how this infrastructure was operated and maintained.
Operational security failures. The insider account touches on the OPSEC failures that contributed to arrests — how affiliates and developers were identified despite using cryptocurrency and Tor. This includes blockchain tracing of ransom payments, operational mistakes that exposed real identities, and the role of traditional law enforcement techniques (informants, legal process to hosting providers) alongside technical tracing.
The decryptor handling. REvil possessed a universal decryptor for the Kaseya attack. The initial $70 million demand went uncollected. Subsequently, a decryptor was provided through a third party, allowing Kaseya to recover affected systems — the circumstances surrounding that decryptor's provision are clarified through the insider account.
Demo / Proof of Concept
This talk does not include a technical exploitation demo. The "proof of concept" is the primary-source intelligence itself — documented conversations, corroborated accounts, and insider details that illuminate the Kaseya attack in ways that are not available from technical analysis alone. DiMaggio and Fokker present their methodology for verifying and corroborating insider claims, including triangulating affiliate accounts against public evidence, other intelligence sources, and law enforcement reporting.
Defensive Implications
Supply-chain attack vectors require supply-chain defenses. The Kaseya attack succeeded because MSPs — the upstream supply chain — were trusted to push software to client environments. Organizations using MSPs or remote management platforms must evaluate the security posture of those platforms as part of their own risk assessment. Supply-chain risk management should include reviewing MSPs' software update and access control practices.
RaaS economics drive the threat landscape. Understanding that REvil affiliates received 70-80% of proceeds while contributing only access and payload deployment illuminates why the affiliate model is so robust — the economics incentivize sophisticated attackers to participate. Defenders should understand that targeting the core developers (as law enforcement did) weakens the platform, but the affiliate talent pool persists and migrates to other platforms.
Incident response must account for negotiation as an adversarial process. REvil's negotiation infrastructure was sophisticated and adversarial — designed to maximize payment. Incident response teams engaging in ransomware negotiations should understand they are dealing with practiced negotiators, not opportunistic criminals, and plan accordingly.
Law enforcement cooperation is essential. The arrests of REvil members in January 2022 represent one of the most significant ransomware disruption actions to date. The talk reinforces that sustained law enforcement pressure — including international cooperation — has real impact on ransomware operations, even when the groups nominally operate in jurisdictions that do not extradite.
Intelligence from human sources supplements technical intelligence. The insights in this talk are not obtainable from malware analysis, network traffic, or dark web forum monitoring alone. Organizations and governments that rely exclusively on technical intelligence for threat understanding are missing a significant dimension of the threat landscape.
Key Takeaways
- REvil's affiliate model enabled the Kaseya attack's unprecedented scale: a single vulnerable supply-chain platform gave affiliates simultaneous access to thousands of organizations, a scenario the affiliates themselves did not fully anticipate.
- Direct insider access provides intelligence about ransomware operations — organizational structure, decision-making, internal conflicts — that is inaccessible through technical means.
- REvil's dissolution following the Kaseya attack was driven by a combination of law enforcement pressure, international diplomatic attention, and internal distrust within the organization.
- The affiliate model's economics (70-80% affiliate cut) explains the persistent supply of sophisticated actors willing to conduct attacks even as core developers are disrupted.
- Supply-chain targeting — attacking management software used by MSPs to administer thousands of clients simultaneously — represents a force multiplier that makes vendor security a critical dependency for every downstream customer.
About the Speaker(s)
Jon DiMaggio is a Chief Security Strategist and threat intelligence researcher known for sustained undercover research into ransomware groups. His prior work includes extended infiltration of the LockBit ransomware operation, which produced some of the most detailed public accounts of RaaS internal operations available. He combines traditional threat intelligence methods with human intelligence tradecraft.
John Fokker is a senior threat intelligence researcher and former law enforcement investigator who has been centrally involved in major international actions against cybercrime organizations. His work spans technical analysis of ransomware platforms and operational collaboration with law enforcement agencies pursuing ransomware operators.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
First-person account of the REvil/Kaseya supply-chain ransomware attack via sustained undercover contact with a direct affiliate. Covers RaaS organizational structure, internal dynamics during dissolution, OPSEC failures, and the human intelligence tradecraft behind obtaining this access. No technical exploitation demo — primary-source intelligence is the content.
Heather Calloway (CISO) — STRONG ACCEPT
DiMaggio and Fokker provide primary-source intelligence on REvil's internal structure and the Kaseya attack from a direct affiliate source — the kind of insider account that technical analysis cannot produce. The governance implications for supply-chain risk management and the economics of the RaaS affiliate model are as important as the operational detail.