Russia Arrests REvil Ransomware Members At U.S. Request

January 17, 2022

In a rare display of cooperation between the U.S. and Russia, Soviet authorities last week launched a sweeping arrest of members of the REVil ransomware gang.

On Friday, the Federal Security Service of the Russian Federation’s partnership with the Ministry of Internal Affairs of Russia resulted in the arrest of 14 people associated with the notorious ransomware group.

In total, 25 residential addresses were searched, which led not only to the arrest of 14 people but also to the seizing of assets of the ransomware gang, which included more than 426 million rubles, €500,000, $600,000 in U.S. dollars, crypto wallets, computer equipment and 20 luxury cars obtained through the gang’s operations.

The court initially identified six men as members of the REvil group: Mikhail Golovachuk, Ruslan Khansvyarov, Dmitry Korotayev, Alexei Malozemov, Artyom Zayets and Daniil Puzyrevsky. They were accused of committing crimes that violated Part 2 of Article 187 “Illegal circulation of means of payment” of the Criminal Code of Russia.

The operation was carried out at the behest of U.S. authorities, and the US was informed of the outcome, according to the FSB.

“The investigative measures were based on a request from the … United States,” the FSB said, according to Reuters. “The organized criminal association has ceased to exist, and the information infrastructure used for criminal purposes was neutralized.”

The group allegedly seized operations last October, when a multi-country operation of law enforcement and cyber experts was able to hack and take control of REvil’s computer network infrastructure. Afterwards, the gang members operated relatively secretly but remained at large.

With the FSB stating that the operation was carried out at the request of the U.S. government, Chris Morgan, senior cyber threats analyst at Digital Shadows, believes that this could be a backhanded message that Russia can in certain circumstances be used to stop ransomware activities.

Morgan added that the FSB may have also carried out raids at REvil, because the arrests would have little impact on the current ransomware landscape, although the gang is a high-profile U.S. target.

For more information, read the original stories in TechRepublic and Reuters.

Top Stories

Related Articles

February 5, 2026 A security researcher at Koi named Oren Yomtov has uncovered a widespread malware operation embedded inside an more...

February 4, 2026 More than three million Fortinet devices have been exposed to a critical authentication-bypass vulnerability that is being more...

February 4, 2026 A now-patched security flaw in Docker’s built-in AI assistant exposed users to the risk of remote code more...

January 28, 2026 A suspected credit card skimming attack on the Canada Computers online store may have quietly exposed customer more...

Picture of TND News Desk

TND News Desk

Staff writer for Tech Newsday.
Picture of TND News Desk

TND News Desk

Staff writer for Tech Newsday.

Jim Love

Jim is an author and podcast host with over 40 years in technology.

Share:
Facebook
Twitter
LinkedIn