GandCrab was a Windows ransomware family operated as a ransomware-as-a-service (RaaS) platform from January 2018 through its announced shutdown in 2019. Its operators supplied customized ransomware builds and supporting infrastructure to affiliates, who retained most ransom proceeds and distributed the malware at scale or used it in targeted enterprise intrusions. GandCrab encrypts victim files and demands cryptocurrency payment for decryption. Some versions also changed the desktop wallpaper and displayed ransom instructions. GandCrab was among the most active ransomware threats in 2018 and the first half of 2019, affecting organizations and individuals globally, with early emphasis on Western countries and later distribution activity in East Asia. Affiliates used email spam, exploit kits, and targeted access through remote-management and remote-access environments. Researchers released multiple free decryptors after implementation errors and compromises affecting GandCrab server-side key material enabled recovery for certain versions. The operation's former ecosystem is widely regarded as a precursor to the REvil/Sodinokibi RaaS operation, although the families are distinct.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In April 2018, Magnitude unexpectedly started pushing the ever-growing GandCrab ransomware, shortly after having adopted a fresh Flash zero-day (CVE-2018-4878).
CVE-2016-7255 Classification: 0-Day Basic Description: Memory corruption in NtUserSetWindowLongPtr ... Found in the following Malware samples: Attributed to APT28 (aka Fancy Bear, Sednit). Used later by Ursnif, Dreambot, GandCrab, Cerber, Maze | Used later by Ursnif, Dreambot, GandCrab, Cerber, Maze
Atlassian Confluence Server and Data Center Widget Connector is vulnerable to a server-side template injection attack... Multiple malware campaigns have taken advantage of this vulnerability; the most notable being GandCrab ransomware. | Multiple malware campaigns have taken advantage of this vulnerability; the most notable being GandCrab ransomware.
One important change in the 5.x version was the inclusion of exploits to elevate privileges. The exploits were CVE-2018-8440 by SandboxEscaper, and CVE-2018-8120. Both exploits were used in Windows 7 and newer OS versions to try to get SYSTEM privileges. With CVE-2018-8120, it tried to steal the system token of the SYSTEM idle process. | This paper examines the GandCrab ransomware, the biggest Ransomware-as-a-Service (RaaS) threat seen in 2018 and the first half of 2019.
One important change in the 5.x version was the inclusion of exploits to elevate privileges. The exploits were CVE-2018-8440 by SandboxEscaper, and CVE-2018-8120. Both exploits were used in Windows 7 and newer OS versions to try to get SYSTEM privileges. | This paper examines the GandCrab ransomware, the biggest Ransomware-as-a-Service (RaaS) threat seen in 2018 and the first half of 2019.
CVE-2019–1367 enables Remote Code Execution (RCE) in the context of Internet explorer in all version from 8, 9, 10 and 11 due to a memory corruption in jscript.dll... Google TAG Team discovered CVE-2019–1367 exploited in the wild by a threat actor.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
TA505 aurait pratiqué un usage ponctuel d’autres rançongiciels (Bart, Jaff, Scarab, Philadelphia, GlobeImposter et GandCrab).
For example, in 2017 TA505 (also known as G0092, GOLD TAHOE) began using GlobeImposter in replacement of Jaff, GandCrab, and Snatch to extend the reach and effectiveness of their campaigns.
Lalartu (AKA Sheriff), a known persona in ransomware since 2019 who played a role in gangs such as GandCrab, REvil, Conti, and others, mentored Basstorlord.
Prior to its development of REvil, the group was associated with an older ransomware family known as Gandcrab.
Storm-0324 has distributed a range of first-stage payloads since at least 2016, including: ... GandCrab ransomware
“…the operators of Gandcrab, GOLD GARDEN, retired and sold their operation to an affiliate group we now call GOLD SOUTHFIELD.”
26 distinct techniques documented for this family, organized by ATT&CK tactic.
Probably the most high-profile attack that GandCrab was behind is a series of infections at customers of remote IT support firms in the month of February.
The GandCrab RaaS is an online portal where crooks sign up and pay to get access to custom builds of the GandCrab ransomware, which they later distribute via email spam, exploit kits, or other means.
“The batch file contained a Base64-encoded PowerShell script that was subsequently executed.” The script used WebClient DownloadString and Invoke-Expression (IEX).
“cmd.exe and powershell.exe are both descendants of the ScreenConnect.WindowsClient.exe process,” and ScreenConnect copied a batch file to endpoints.
This Word document contains a macro that downloads and executes the Gandcrab ransomware. | During the course of the campaign, we also saw emails that included VBScript files instead of a ZIP file. The end result is the same, with the payload being pulled off of the server.
“PowerShell... was leveraged in an attempt to inject shellcode into itself” and Elastic prevented several process-injection attempts.
“The batch file contained a Base64-encoded PowerShell script that was subsequently executed.”
“PowerShell... was leveraged in an attempt to inject shellcode into itself” and Elastic prevented several process-injection attempts.
Probably the most high-profile attack that GandCrab was behind is a series of infections at customers of remote IT support firms in the month of February.
With CVE-2018-8120, it tried to steal the system token of the SYSTEM idle process.
GandCrab’s aggressive distribution network was built through its affiliate program and partnerships with other services, such as the binary crypter NTCrypt, along with other actors with expertise in distribution through RDP and VNC.
Crabs only said only 'good work,' admitting that the Romanian antivirus firm had gained access to one of the GandCrab C&C servers from where they took the encryption/decryption keys fair and square.
These two new GandCrab versions contained the alleged exploit code targeting AhnLab antivirus versions... 'The attack code is inserted in GandCrab 4.21 and 4.3 version, and it is executed after infecting normal files,' AhnLab Director Changkyu Han told Bleeping Computer.
82 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
123 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware family explicitly linked in the content to Media Land / yalishanda infrastructure.
Related Articles: ... German authorities identify REvil and GandCrab ransomware bosses ...
Prolific ransomware family first seen in early 2018, responsible for significant global financial damage before being succeeded by REvil/Sodinokibi.
A ransomware family operated as a ransomware-as-a-service platform, primarily distributed through spam emails, used for extortion by encrypting data and threatening non-publication/decryption unless ransom was paid.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.