Reveton — Ransomware Profile

Reveton is a police-themed screen-locking ransomware family that surfaced in 2011, with Microsoft cataloguing it as Ransom:Win32/Reveton.A on 22 November 2011. Rather than encrypting files, it froze the desktop behind a full-screen notice impersonating the victim's local police force and demanding payment of a bogus fine; the German-language build was known as the BKA Trojan. CERT-IST reported that, according to most analyses, delivery came through the BlackHole exploit kit, which scanned the browser and third-party plugins such as Java, Flash and Adobe Reader for a way in, while the ransom itself was collected through prepaid voucher services that varied by the victim's country. In August 2014 Avast analysed a build that bolted the Pony credential stealer onto the locker, extending it from a lock screen into a password and cryptocurrency-wallet thief. Prosecutors have described Reveton as the first ransomware-as-a-service business model, and Barracuda notes the strain tapered off during 2014. Its alleged creator, Belarusian national Maksim Silnikau, was sentenced to 16 years in prison, with prosecutors putting the scheme's proceeds at roughly $400,000 a month between 2012 and 2014.

Also tracked as

BKA Trojan

Vendor research

Read the full analysis on IntelFusions