Revils Ransomware Success Formula Constant Innovation Showcase Image 7 A 16976

Experts say that an affiliate-driven approach and regular malware refinements are key to REvil's ransomware success formula.

Just as cloud services have taken the business world by storm, the same can be said for ransomware, including one of today's most notorious strains: REvil. Also known as Sodinokibi and Sodin, REvil is a ransomware-as-a-service offering, which means a core group develops and maintains the ransomware code and makes it available to affiliates via a portal.

Those affiliates and the core group of operators share in any profits that result from victims paying a ransom. Recent victims that have made payments include meat processor JBS, which paid $11 million in bitcoins.

On Friday, remote management software provider Kaseya was the latest victim to come to light, as REvil's ransomware disrupted operations for its 36,000 customers worldwide, leading U.S. President Joe Biden to order the launch of a full-scale federal investigation.