GandCrab was a prolific ransomware-as-a-service (RaaS) operation active from early 2018 until mid-2019 and is widely regarded as one of the most consequential ransomware programs of that period. It pioneered and popularized an aggressive affiliate-driven business model for large-scale ransomware deployment, with operators providing the malware and payment infrastructure while affiliates handled victim access, distribution, and execution. Revenue sharing reportedly favored affiliates and helped GandCrab build a broad criminal partner ecosystem that included exploit-kit operators, crypter services, and actors specializing in remote-access compromise. GandCrab spread through multiple intrusion and delivery channels, including exploit kits, spam and malvertising campaigns, compromised remote administration pathways such as RDP and VNC, and software supply-chain abuse affecting managed service provider environments. The operation was observed targeting Western countries, especially in Latin America, and later expanded activity into Asia, including South Korea and China. Victims were reported across nearly 100 countries. GandCrab also showed repeated interest in MSP-centric propagation and was linked to abuse of a Kaseya-related plugin vulnerability to push ransomware into downstream customer networks. Technically, GandCrab evolved rapidly across many versions, adopting agile release cycles and frequent feature changes. Researchers documented anti-analysis and anti-recovery behavior, selective language checks to avoid systems in CIS locales, deletion of shadow copies, collection of host metadata, and later use of privilege-escalation exploits including CVE-2018-8440 and CVE-2018-8120. The malware embedded affiliate identifiers in later versions, enabling tracking of affiliate activity. GandCrab also engaged in active defense evasion and product-specific countermeasures, most notably a prolonged contest with AhnLab in which the operators repeatedly modified code to bypass, disable, uninstall, or inject around defensive tooling. The operation was notable not only for encryption but also for pre-encryption monetization. GandCrab distributors were observed adding the Vidar infostealer to steal credentials and other sensitive data before file encryption, increasing profitability through both ransom collection and resale of stolen information. This demonstrates that the group and its affiliates combined ransomware with credential theft and data exfiltration workflows. GandCrab’s operators cultivated a public persona unusual for ransomware groups, taunting researchers and vendors, using security reporting in their own promotion, and aggressively marketing the service on Russian-language criminal forums. Despite its operational success, GandCrab repeatedly suffered from implementation mistakes and infrastructure exposure. Coding flaws and compromises of server-side infrastructure enabled multiple public decryptors and vaccines, including releases supported by Bitdefender and Europol. The group announced its retirement in mid-2019 after claiming very large profits, though such claims were likely inflated. GandCrab is broadly considered a predecessor or lineage source for REvil/Sodinokibi, with reported overlap in operators, affiliates, code lineage, and criminal ecosystem relationships.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
44 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a comparison/denial of affiliation with BlackCat.
Threat actor/group associated in the content with use of Media Land bulletproof hosting infrastructure.
A major ransomware-as-a-service operation linked to large-scale extortion against organizations, primarily using spam emails, and later evolving into REvil.
Ransomware operation allegedly led by Daniil Maksimovich Shchukin and associated with computer sabotage and extortion.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.