GandCrab
GandCrab is a ransomware family and ransomware-as-a-service (RaaS) operation that launched in January 2018 and was active until its operators announced retirement in May 2019. The operation was primarily spread through spam emails, and the content also links GandCrab distribution to campaigns leveraging hijacked or abused GoDaddy-hosted domains in early 2019. GandCrab was also distributed by other criminal actors such as Storm-0324, and other malware families such as Ursnif were observed deploying GandCrab as a follow-on payload.
The malware is associated with a broad affiliate ecosystem rather than a single intrusion set. The content identifies sprite77 as a known GandCrab affiliate and notes that some affiliates later moved to REvil/Sodinokibi. Multiple law-enforcement and reporting sources in the content describe REvil as a successor to GandCrab, with source-code and behavioral similarities suggesting continuity between the two operations. German authorities identified Daniil Maksimovich Shchukin, also known as UNKN/Unknown, as a leader of GandCrab and later REvil, and also named Anatoly Sergeevitsch Kravchuk as a suspected developer involved in the malware and extortion platform. Europol-supported investigations since 2018 targeted GandCrab and later affiliates tied to both GandCrab and REvil.
The content characterizes GandCrab as highly prolific and financially successful. Its operators claimed to have collected more than $2 billion in ransom payments, and one source cites more than one million victims worldwide. The FBI estimate cited in the content says GandCrab caused more than $300 million in damages. Law-enforcement actions led to the release of multiple decryptors via the No More Ransom project, including tools for GandCrab versions V1, V4, and V5 through V5.2; these reportedly enabled tens of thousands of decryptions and prevented substantial ransom losses.
Technical details in the content are limited compared with REvil, but GandCrab is explicitly described as ransomware and as part of the RaaS family. One cited study analyzed GandCrab network traffic alongside Ryuk to generate packet signatures for early detection. Another source notes that GandCrab, like Sodinokibi, used reflective DLL loaders to load dynamic libraries directly into process memory without standard Windows API usage. No specific ransom-note filenames, file extensions, mutexes, registry keys, or hashes for GandCrab itself are provided in the content.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Vulnerabilities exploited
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Multiple malware campaigns have taken advantage of this vulnerability; the most notable being GandCrab ransomware. | Atlassian Confluence Server and Data Center Widget Connector is vulnerable to a server-side template injection attack... Multiple malware campaigns have taken advantage of this vulnerability; the most notable being GandCrab ransomware.
Groups observed using it
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Due to source code and behavior similarities between REvil and GandCrab, it was suggested there might be a connection tying the developers of the two ransomware families together.
Storm-0324 has distributed a range of first-stage payloads since at least 2016, including: ... GandCrab ransomware
“…the operators of Gandcrab, GOLD GARDEN, retired and sold their operation to an affiliate group we now call GOLD SOUTHFIELD.”
Techniques & procedures
16 distinct techniques documented for this family, organized by ATT&CK tactic.
Resource Development
1 technique
Resource Development
In January 2019, it was reported that some domains that were registered at GoDaddy had been sending ransom bomb threats... These messages appeared to be from domains owned by legitimate, well-known brands. The group... was exploiting a vulnerability in GoDaddy’s DNS setup platform... They would then use the automated service to send mail from dormant domains.
Initial Access
3 techniques
Initial Access
The Gandcrab ransomware affiliate program first surfaced in January 2018, and paid enterprising hackers huge shares of the profits just for hacking into user accounts at major corporations.
Execution
3 techniques
Execution
A primary suspect for malicious code download and in-memory execution in the recent period is PowerShell... PowerShell is launched with Invoke-Expression cmdlet evaluating code downloaded from a Pastebin web page using the Net.WebClient.DownloadString function, which downloads a web page as a string and stores it in memory.
Citrix ADC maintains a vulnerable Perl script (newbm.pl) that, when accessed via HTTP POST request ... allows local operating system (OS) commands to execute. Attackers can use this functionality to upload/execute command and control (C2) software ... and gain unauthorized access to the OS.
Persistence
1 technique
Persistence
Privilege Escalation
1 technique
Privilege Escalation
Stealth
5 techniques
Stealth
Obfuscation and polymorphic nature of malware make them more difficult to identify by Antivirus system.
Obfuscation and polymorphic nature of malware make them more difficult to identify by Antivirus system.
The Gandcrab ransomware affiliate program first surfaced in January 2018, and paid enterprising hackers huge shares of the profits just for hacking into user accounts at major corporations.
One popular technique we're seeing at this time is the use of living-off-the-land binaries — or "LoLBins"... LoLBins are used by different actors combined with fileless malware and legitimate cloud services to improve chances of staying undetected within an organisation, usually during post-exploitation attack phases.
Popular malware like Sodinokibi and Gandcrab have used reflect DLL loaders in the past that allows attackers to load a dynamic library into process memory without using Windows API... the obfuscated Cobalt Strike beacon... gets deobfuscated with a static XOR key and loaded into memory using reflective loading techniques.
Exfiltration
3 techniques
Exfiltration
The Gandcrab team would then try to expand that access, often siphoning vast amounts of sensitive and internal documents in the process.
Recent activity
46 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Related Articles: ... German authorities identify REvil and GandCrab ransomware bosses ...
Prolific ransomware family first seen in early 2018, responsible for significant global financial damage before being succeeded by REvil/Sodinokibi.
A ransomware family operated as a ransomware-as-a-service platform, primarily distributed through spam emails, used for extortion by encrypting data and threatening non-publication/decryption unless ransom was paid.
Ransomware operation allegedly run by the actor known as UNKN, active from January 2018 until May 2019 and reported to have collected over $2 billion in ransom payments.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.