Law enforcement and industry partners released a free No More Ransom decryption tool for victims of GandCrab ransomware, offering recovery support for most known variants of one of 2018’s most widespread ransomware families. Europol said the tool was developed with the Romanian Police, international law enforcement partners, and Bitdefender, and came after GandCrab had infected nearly half a million victims worldwide while demanding payments ranging from $300 to $6,000 in Bitcoin or DASH. The release marked a significant disruption of a ransomware-as-a-service operation that had scaled rapidly through affiliate partnerships across the cybercrime ecosystem.
GandCrab had spread through multiple delivery channels, including malspam campaigns disguised as receipts or order notices and payloads hosted on compromised legitimate websites. Reporting from Cisco Talos and BleepingComputer described infection chains using ZIP archives, macro-enabled Word documents, VBScript, fake CAPTCHA pages, and PowerShell-based downloaders, with some campaigns also abusing compromised sites and certutil.exe to retrieve payloads. Once executed, GandCrab encrypted files, appended the .CRAB extension, altered desktop wallpapers, and communicated through infrastructure including Tor and Namecoin .bit domains, underscoring both the scale of the threat and the practical value of the newly released decryptor.

TTPs, infrastructure, and targeting history in one profile.
11 events from the most recent confirmed update back to the earliest known activity.
About two weeks before Fortinet's June 24, 2019 article, GandCrab's operators publicly announced they had shut down the ransomware-as-a-service operation. The actors claimed the enterprise generated $2 billion in total earnings and that they personally made $150 million.
A new free decryption tool for GandCrab was released on No More Ransom, developed by the Romanian Police with international law enforcement partners, Bitdefender, and Europol. Europol described it as the most comprehensive decryptor then available, supporting all but two GandCrab versions mentioned in the article.
Talos observed further GandCrab spam campaigns on May 5 and May 7, reusing compromised sites including pushpakcourier[.]net and herbal-treatment-advisory[.]com to host malware.
Talos observed a second wave beginning on May 2, 2018, with nearly identical lures and attachments. One payload was hosted on pushpakcourier[.]net, which Talos assessed as a compromised legitimate website.
Cisco Talos observed a large-scale spam campaign beginning on April 30, 2018, using 'Your Order #{Random Digits}' lures and malicious attachments to deliver GandCrab payloads.
A malspam campaign distributed GandCrab through emails disguised as PDF receipts. The infection chain used a fake CAPTCHA, a malicious Word document, and macros that launched PowerShell to download and run the ransomware.
Europol said a first GandCrab decryption tool was made available in February through No More Ransom by the Romanian Police with support from Bitdefender and Europol.
Europol said GandCrab had infected nearly half a million victims since it was first detected in January 2018, marking the emergence of the ransomware family.
A week before the universal decryptor release, the GandCrab group published decryption keys that only helped a limited pool of victims in Syria.
Europol reported that a third version of GandCrab was released one day after the second version, showing the operators' rapid iteration to evade countermeasures.
After the first decryptor was released, GandCrab's operators issued a second version that included comments intended to provoke law enforcement, security companies, and No More Ransom.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 25 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
6 references tracked. Mallory keeps watching after this page renders.
labs.bitdefender.com
Open sourcefortinet.com
Open sourceeuropol.europa.eu
Open sourceblog.talosintelligence.com
Open sourcebleepingcomputer.com
Open sourcenomoreransom.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.