Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
MalwareRansomwareUsed by 3 actorsExploits 1 CVE

GandCrab

GandCrab is a ransomware family and ransomware-as-a-service (RaaS) operation that launched in January 2018 and was active until its operators announced retirement in May 2019. The operation was primarily spread through spam emails, and the content also links GandCrab distribution to campaigns leveraging hijacked or abused GoDaddy-hosted domains in early 2019. GandCrab was also distributed by other criminal actors such as Storm-0324, and other malware families such as Ursnif were observed deploying GandCrab as a follow-on payload.

The malware is associated with a broad affiliate ecosystem rather than a single intrusion set. The content identifies sprite77 as a known GandCrab affiliate and notes that some affiliates later moved to REvil/Sodinokibi. Multiple law-enforcement and reporting sources in the content describe REvil as a successor to GandCrab, with source-code and behavioral similarities suggesting continuity between the two operations. German authorities identified Daniil Maksimovich Shchukin, also known as UNKN/Unknown, as a leader of GandCrab and later REvil, and also named Anatoly Sergeevitsch Kravchuk as a suspected developer involved in the malware and extortion platform. Europol-supported investigations since 2018 targeted GandCrab and later affiliates tied to both GandCrab and REvil.

The content characterizes GandCrab as highly prolific and financially successful. Its operators claimed to have collected more than $2 billion in ransom payments, and one source cites more than one million victims worldwide. The FBI estimate cited in the content says GandCrab caused more than $300 million in damages. Law-enforcement actions led to the release of multiple decryptors via the No More Ransom project, including tools for GandCrab versions V1, V4, and V5 through V5.2; these reportedly enabled tens of thousands of decryptions and prevented substantial ransom losses.

Technical details in the content are limited compared with REvil, but GandCrab is explicitly described as ransomware and as part of the RaaS family. One cited study analyzed GandCrab network traffic alongside Ryuk to generate packet signatures for early detection. Another source notes that GandCrab, like Sodinokibi, used reflective DLL loaders to load dynamic libraries directly into process memory without standard Windows API usage. No specific ransom-note filenames, file extensions, mutexes, registry keys, or hashes for GandCrab itself are provided in the content.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

1 CVES
CVE-2019-3396Atlassian Confluence Widget Connector SSTI RCEExploited in the wild

Multiple malware campaigns have taken advantage of this vulnerability; the most notable being GandCrab ransomware. | Atlassian Confluence Server and Data Center Widget Connector is vulnerable to a server-side template injection attack... Multiple malware campaigns have taken advantage of this vulnerability; the most notable being GandCrab ransomware.

via ic3 alertsic3.gov
THREAT ACTORS

Groups observed using it

3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
lalartu

Due to source code and behavior similarities between REvil and GandCrab, it was suggested there might be a connection tying the developers of the two ransomware families together.

via intel471intel471.com
Storm-0324

Storm-0324 has distributed a range of first-stage payloads since at least 2016, including: ... GandCrab ransomware

via microsoft generalmicrosoft.com
GOLD GARDEN

“…the operators of Gandcrab, GOLD GARDEN, retired and sold their operation to an affiliate group we now call GOLD SOUTHFIELD.”

via the record mediatherecord.media
MITRE ATT&CK

Techniques & procedures

16 distinct techniques documented for this family, organized by ATT&CK tactic.

Resource Development

1 technique
T1584Compromise InfrastructureEvidence1

In January 2019, it was reported that some domains that were registered at GoDaddy had been sending ransom bomb threats... These messages appeared to be from domains owned by legitimate, well-known brands. The group... was exploiting a vulnerability in GoDaddy’s DNS setup platform... They would then use the automated service to send mail from dormant domains.

Initial Access

3 techniques
T1078Valid AccountsEvidence1

The Gandcrab ransomware affiliate program first surfaced in January 2018, and paid enterprising hackers huge shares of the profits just for hacking into user accounts at major corporations.

T1190Exploit Public-Facing ApplicationEvidence1

A remote attacker is able to exploit a server-side request forgery (SSRF) vulnerability in the WebDAV plugin to send arbitrary HTTP and WebDAV requests from a Confluence Server or Data Center instance.

T1566PhishingEvidence3

These messages appeared to be from domains owned by legitimate, well-known brands... They would then use the automated service to send mail from dormant domains.

Execution

3 techniques
T1059.001PowerShellEvidence1

A primary suspect for malicious code download and in-memory execution in the recent period is PowerShell... PowerShell is launched with Invoke-Expression cmdlet evaluating code downloaded from a Pastebin web page using the Net.WebClient.DownloadString function, which downloads a web page as a string and stores it in memory.

T1203Exploitation for Client ExecutionEvidence1

Citrix ADC maintains a vulnerable Perl script (newbm.pl) that, when accessed via HTTP POST request ... allows local operating system (OS) commands to execute. Attackers can use this functionality to upload/execute command and control (C2) software ... and gain unauthorized access to the OS.

T1204.002Malicious FileEvidence1

First advertised in early 2018, GandCrab initially spread through spam emails containing malicious attachments.

Persistence

1 technique
T1078Valid AccountsEvidence1

The Gandcrab ransomware affiliate program first surfaced in January 2018, and paid enterprising hackers huge shares of the profits just for hacking into user accounts at major corporations.

Privilege Escalation

1 technique
T1078Valid AccountsEvidence1

The Gandcrab ransomware affiliate program first surfaced in January 2018, and paid enterprising hackers huge shares of the profits just for hacking into user accounts at major corporations.

Stealth

5 techniques
T1027Obfuscated Files or InformationEvidence1

Obfuscation and polymorphic nature of malware make them more difficult to identify by Antivirus system.

T1027.014Polymorphic CodeEvidence1

Obfuscation and polymorphic nature of malware make them more difficult to identify by Antivirus system.

T1078Valid AccountsEvidence1

The Gandcrab ransomware affiliate program first surfaced in January 2018, and paid enterprising hackers huge shares of the profits just for hacking into user accounts at major corporations.

T1218System Binary Proxy ExecutionEvidence1

One popular technique we're seeing at this time is the use of living-off-the-land binaries — or "LoLBins"... LoLBins are used by different actors combined with fileless malware and legitimate cloud services to improve chances of staying undetected within an organisation, usually during post-exploitation attack phases.

T1620Reflective Code LoadingEvidence1

Popular malware like Sodinokibi and Gandcrab have used reflect DLL loaders in the past that allows attackers to load a dynamic library into process memory without using Windows API... the obfuscated Cobalt Strike beacon... gets deobfuscated with a static XOR key and loaded into memory using reflective loading techniques.

Exfiltration

3 techniques
T1041Exfiltration Over C2 ChannelEvidence1

The Gandcrab team would then try to expand that access, often siphoning vast amounts of sensitive and internal documents in the process.

T1537Transfer Data to Cloud AccountEvidence2

In addition, in some cases, extensive data were also spied on and threatened with the publication of this, unless a ransom was paid.

T1567Exfiltration Over Web ServiceEvidence1

...pioneered the practice of double extortion — charging victims once for a key needed to unlock hacked systems, and a separate payment in exchange for a promise not to publish stolen data.

Impact

2 techniques
T1486Data Encrypted for ImpactEvidence16

- 08.20.2019 16:56:51 Release date Panel is ready Cryptolocker is ready ... - 10.02.2019 15:28:23 1.6 ransomware update changed encryption algorithm added our own key generator (not pseudo keys)

T1657Financial TheftEvidence1

The perpetrators demanded large ransom payments in exchange for decrypting and not leaking data.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution3

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities1

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping16

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.