HIGHRansomware
Global

BKA Identifies REvil Leaders Behind 130 German Ransomware Attacks

Monday, April 6, 2026 at 06:59 AM UTC·Source: The Hacker News

Updated: Monday, April 6, 2026 at 07:04 AM UTC

Executive Summary

Germany's Federal Criminal Police Office (aka BKA or the Bundeskriminalamt) has unmasked the real identity of the main threat actors associated with the now-defunct REvil (aka Sodinokibi) ransomware-as-a-service (RaaS) operation. The threat actor, who went by the alias UNKN, functioned as a representative of the group, advertising the ransomware in June 2019 on the XSS cybercrime forum. He

Analysis

Germany's Federal Criminal Police Office (aka BKA or the Bundeskriminalamt) has unmasked the real identity of the main threat actors associated with the now-defunct REvil (aka Sodinokibi) ransomware-as-a-service (RaaS) operation. The threat actor, who went by the alias UNKN, functioned as a representative of the group, advertising the ransomware in June 2019 on the XSS cybercrime forum. He
Source Attribution

Originally published by The Hacker News on Apr 6, 2026.

Related Threats