BKA Identifies REvil Leaders Behind 130 German Ransomware Attacks

BKA Identifies REvil Leaders Behind 130 German Ransomware Attacks

BKA Identifies REvil Leaders Behind 130 German Ransomware Attacks

https://thehackernews.com/2026/04/bka-identifies-revil-leaders-behind-130.html

Publish Date: 2026-04-06 02:59:00

Source Domain: thehackernews.com

Ravie LakshmananApr 06, 2026Cybercrime / Financial Crime

Germany’s Federal Criminal Police Office (aka BKA or the Bundeskriminalamt) has unmasked the real identity of the main threat actors associated with the now-defunct REvil (aka Sodinokibi) ransomware-as-a-service (RaaS) operation.

The threat actor, who went by the alias UNKN, functioned as a representative of the group, advertising the ransomware in June 2019 on the XSS cybercrime forum. He has now been identified as Daniil Maksimovich Shchukin, a 31-year-old Russian national. He also went by the online monikers Oneiilk2, Oneillk2, Oneillk22, and GandCrab.

The development was reported by independent security journalist Brian Krebs.

“From early 2019 at the latest until at least July 2021, the wanted person, in cooperation with other individuals, acted as the leader of one of the largest global ransomware groups, known as GandCrab/REvil,” BKA said. “The perpetrators demanded large ransom payments in exchange for decrypting and not leaking data.”

Also added to the wanted list is Anatoly Sergeevitsch Kravchuk, a 43-year-old Russian born in the Ukrainian city of Makiivka. He is alleged to have acted as the developer of REvil during the same time period.

Shchukin and Kravchuk are suspected of having carried out 130 ransomware attacks across Germany. Out of these, 25 cases led to the payment of €1.9 million ($2.19 million). The incidents collectively incurred financial damages exceeding €35.4 million ($40.8 million).

REvil (aka Water Mare and Gold Southfield) was one of the prolific ransomware groups that counted companies like JBS and Kaseya among its victims. An evolution of the GandCrab ransomware, the e-crime crew mysteriously went offline in mid-July 2021, only to resurface in two months later.

By October 2021, the group ceased operations, and its data leak site became inaccessible as part of a law enforcement operation. Weeks later, Romanian law enforcement…

Source