Hacked
Hacked

REvil Redux

April 16, 2026

AI Summary

5 min read

In December 2023, a researcher took the stage at the Chaos Communication Congress in Hamburg and named a 31-year-old Russian man, Daniel Maksimovich Shukin, as the person behind the most elusive handle in ransomware history: UNKN. For years, all anyone had was that username from a Russian cybercrime forum, pointing toward the architect of some of the most destructive ransomware operations the world had ever seen. The German Federal Criminal Police (BKA) made the identification official in April 2026, charging Shukin with at least 130 acts of computer sabotage and extortion against victims in Germany between 2019 and 2021, costing more than 35 million euros in total economic damage.

The Rise of GandCrab and REvil

Shukin’s alleged operation began with a ransomware shop called GandCrab, which launched in 2018. It was a franchise model—ransomware-as-a-service—where Shukin and his team built the malware that other criminals paid to use, handing back 30 to 40 cents on every dollar extorted. Within roughly a year and a half, GandCrab extorted over $2 billion from victims before abruptly shutting down in May 2019 with a farewell message: "We are living proof that you can do evil and get off scot-free."

Continue reading the full summary in the app — free to try.

Read Full Summary →

Free • No credit card required

What you'll learn

  • 1 (00:00) **The Unmasking of Unknown** - German federal police officially reveal the identity of the elusive ransomware operator known as "Unknown," tying him to the GandCrab and REvil operations.
  • 2 (03:04) **The Long Road to a Name** - Private researchers publicly named Shukin a year before the BKA announcement, building on a DOJ filing that had already included his name and address.
  • 3 (07:36) **GandCrab: The Franchise Ransomware Empire** - The hosts trace the origin story of Shukin's first major operation, GandCrab, which extorted an estimated $2 billion in under two years.
  • 4 (09:45) **REvil: Going Upmarket** - Within weeks of GandCrab's shutdown, REvil emerged with the same team, bigger targets, and a refined approach to double extortion.
  • 5 (13:19) **The FBI's Dilemma** - The FBI had infiltrated REvil's servers before the Kaseya attack but chose to withhold the decryption key for three weeks to protect a larger operation.
  • 6 (15:48) **The Russian Arrests and the War** - In a rare move, Russia's FSB arrested 14 REvil members in January 2022, but the diplomatic credit vanished when Russia invaded Ukraine a month later.
  • 7 (20:08) **What the BKA Announcement Actually Means** - The German police's naming of Shukin is an attribution, not an arrest, and he is believed to be in Russia, which does not extradite its citizens.

+ Full timestamped outline available in the app

Show Notes

We return to one of the more interesting ransomware as a service stories of the last few years; the story of REvil and it's recently (allegedly) named operator. Also the big mythical thing that happened.

Learn more about your ad choices. Visit podcastchoices.com/adchoices

Hacked

More from this podcast

Hacked →