GandCrab was a financially motivated ransomware-as-a-service operation active from January 2018 until its shutdown in late May and early June 2019. Its developers supplied ransomware and supporting infrastructure to affiliates, who distributed the malware in exchange for a majority share of ransom payments, typically 60–70%. The operation affected victims worldwide, including individuals, businesses, managed service providers (MSPs), and their downstream customers. REvil, also known as Sodinokibi, subsequently emerged as its successor, with links involving malware code and participants; it was a distinct operation rather than simply another GandCrab alias. GandCrab distribution included malicious email, drive-by downloads, malvertising, the Fallout and RIG exploit kits, and partnerships with actors distributing malware through RDP and VNC. In February 2019, GandCrab attackers exploited a vulnerability in the ConnectWise integration with Kaseya VSA to deploy ransomware through MSP infrastructure, affecting 126 Kaseya customers. Some distribution campaigns deployed the Vidar infostealer before GandCrab, stealing browser credentials and other sensitive information before file encryption. Later GandCrab versions used Salsa20 for file encryption and RSA to protect encryption keys. The malware collected detailed host information, deleted Volume Shadow Copies to inhibit recovery, and used Windows privilege-escalation exploits including CVE-2018-8440 and CVE-2018-8120. It checked system language settings to avoid encrypting systems configured with selected Commonwealth of Independent States languages. Its defense-evasion techniques included crypter services, delayed execution, security-product removal or service termination, and injection into an AhnLab update process. The operation was distinguished by rapid development, aggressive affiliate recruitment, and repeated adaptations against security-vendor countermeasures. Implementation flaws and compromises of its server-side infrastructure enabled free decryption tools, with expanded recovery support becoming available after its shutdown.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
44 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a comparison/denial of affiliation with BlackCat.
Threat actor/group associated in the content with use of Media Land bulletproof hosting infrastructure.
A major ransomware-as-a-service operation linked to large-scale extortion against organizations, primarily using spam emails, and later evolving into REvil.
Ransomware operation allegedly led by Daniil Maksimovich Shchukin and associated with computer sabotage and extortion.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.