GandCrab is a Windows file-encrypting ransomware family first observed in January 2018 and operated through a ransomware-as-a-service model. It encrypts victims’ files and leaves ransom instructions demanding payment for recovery. Its distribution involved multiple criminal affiliates and delivery operators, including Storm-0324, and affected individuals, corporate environments, and customers of managed service providers. The operation ceased in 2019; REvil, also known as Sodinokibi, is recognized as its successor.
GandCrab was distributed through malicious spam, social-engineering campaigns, and the RIG, GrandSoft, and Magnitude exploit kits. Phishing campaigns included Valentine’s Day-themed emails targeting companies. Attackers also deployed it by exploiting public-facing applications, including Oracle WebLogic Server through CVE-2019-2725 and Atlassian Confluence through CVE-2019-3396. In February 2019, exploitation of a vulnerability in the ConnectWise plugin for Kaseya VSA affected 126 Kaseya customers, illustrating its use of remote-management infrastructure to reach downstream organizations.
A Magnitude campaign focused on South Korea used an encoded scriptlet to load GandCrab in memory and inject its payload into Windows Explorer, reducing disk-based exposure. GandCrab versions 4.2.1 and 4.3 also incorporated code capable of crashing an AhnLab antivirus component and, in some cases, causing a Windows blue screen. This behavior was a denial-of-service mechanism rather than a demonstrated code-execution exploit. Free decryption tools have been released for some GandCrab versions, but recovery support is version-dependent.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In the weeks since the publication of the advisory, attackers have been probing for and exploiting CVE-2019-3396 on vulnerable systems.
Malwarebytes users are protected against this attack when either the Internet Explorer (CVE-2016-0189) or Flash Player (CVE-2018-4878) exploits are fired.
Malicious activity exploiting the recently disclosed Oracle WebLogic critical deserialization vulnerability (CVE-2019-2725) is surging. Payloads include Sodinokibi, Muhstik, XMRig, and GandCrab.
Malwarebytes users are protected against this attack when either the Internet Explorer (CVE-2016-0189) or Flash Player (CVE-2018-4878) exploits are fired.
Gandcrab was next with 11 vulnerabilities, 9 trending.
Gandcrab was next with 11 vulnerabilities, 9 trending.
Gandcrab was next with 11 vulnerabilities, 9 trending.
Gandcrab was next with 11 vulnerabilities, 9 trending.
CVE-2016-7255 Classification: 0-Day Basic Description: Memory corruption in NtUserSetWindowLongPtr ... Found in the following Malware samples: Attributed to APT28 (aka Fancy Bear, Sednit). Used later by Ursnif, Dreambot, GandCrab, Cerber, Maze | Used later by Ursnif, Dreambot, GandCrab, Cerber, Maze
One important change in the 5.x version was the inclusion of exploits to elevate privileges. The exploits were CVE-2018-8440 by SandboxEscaper, and CVE-2018-8120. Both exploits were used in Windows 7 and newer OS versions to try to get SYSTEM privileges. With CVE-2018-8120, it tried to steal the system token of the SYSTEM idle process. | This paper examines the GandCrab ransomware, the biggest Ransomware-as-a-Service (RaaS) threat seen in 2018 and the first half of 2019.
One important change in the 5.x version was the inclusion of exploits to elevate privileges. The exploits were CVE-2018-8440 by SandboxEscaper, and CVE-2018-8120. Both exploits were used in Windows 7 and newer OS versions to try to get SYSTEM privileges. | This paper examines the GandCrab ransomware, the biggest Ransomware-as-a-Service (RaaS) threat seen in 2018 and the first half of 2019.
CVE-2019–1367 enables Remote Code Execution (RCE) in the context of Internet explorer in all version from 8, 9, 10 and 11 due to a memory corruption in jscript.dll... Google TAG Team discovered CVE-2019–1367 exploited in the wild by a threat actor.
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In February 2019, the GandCrab ransomware group exploited a two-year old vulnerability in the ConnectWise plugin for Kaseya VSA, which affected 126 Kaseya customers.
Storm-0324's historical payload list includes “Sage, Gandcrab Ransomware.”
TA505 aurait pratiqué un usage ponctuel d’autres rançongiciels (Bart, Jaff, Scarab, Philadelphia, GlobeImposter et GandCrab).
For example, in 2017 TA505 (also known as G0092, GOLD TAHOE) began using GlobeImposter in replacement of Jaff, GandCrab, and Snatch to extend the reach and effectiveness of their campaigns.
Lalartu (AKA Sheriff), a known persona in ransomware since 2019 who played a role in gangs such as GandCrab, REvil, Conti, and others, mentored Basstorlord.
Prior to its development of REvil, the group was associated with an older ransomware family known as Gandcrab.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
Probably the most high-profile attack that GandCrab was behind is a series of infections at customers of remote IT support firms in the month of February.
The GandCrab RaaS is an online portal where crooks sign up and pay to get access to custom builds of the GandCrab ransomware, which they later distribute via email spam, exploit kits, or other means.
“The batch file contained a Base64-encoded PowerShell script that was subsequently executed.” The script used WebClient DownloadString and Invoke-Expression (IEX).
“cmd.exe and powershell.exe are both descendants of the ScreenConnect.WindowsClient.exe process,” and ScreenConnect copied a batch file to endpoints.
This Word document contains a macro that downloads and executes the Gandcrab ransomware. | During the course of the campaign, we also saw emails that included VBScript files instead of a ZIP file. The end result is the same, with the payload being pulled off of the server.
“PowerShell... was leveraged in an attempt to inject shellcode into itself” and Elastic prevented several process-injection attempts.
“The batch file contained a Base64-encoded PowerShell script that was subsequently executed.”
“PowerShell... was leveraged in an attempt to inject shellcode into itself” and Elastic prevented several process-injection attempts.
Probably the most high-profile attack that GandCrab was behind is a series of infections at customers of remote IT support firms in the month of February.
With CVE-2018-8120, it tried to steal the system token of the SYSTEM idle process.
GandCrab’s aggressive distribution network was built through its affiliate program and partnerships with other services, such as the binary crypter NTCrypt, along with other actors with expertise in distribution through RDP and VNC.
Crabs only said only 'good work,' admitting that the Romanian antivirus firm had gained access to one of the GandCrab C&C servers from where they took the encryption/decryption keys fair and square.
These two new GandCrab versions contained the alleged exploit code targeting AhnLab antivirus versions... 'The attack code is inserted in GandCrab 4.21 and 4.3 version, and it is executed after infecting normal files,' AhnLab Director Changkyu Han told Bleeping Computer.
89 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
142 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware listed as historically distributed by Storm-0324. No direct relationship to the analyzed JSSLoader infection chain is established.
Ransomware family explicitly linked in the content to Media Land / yalishanda infrastructure.
Related Articles: ... German authorities identify REvil and GandCrab ransomware bosses ...
Prolific ransomware family first seen in early 2018, responsible for significant global financial damage before being succeeded by REvil/Sodinokibi.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.