GandCrab grew into one of the most prominent ransomware-as-a-service (RaaS) operations by pairing frequent malware updates with a broad affiliate program, exploit-kit distribution, and supporting criminal services such as crypters. Technical analyses found the malware used anti-analysis and anti-recovery features, selective language checks to avoid CIS targets, privilege-escalation exploits in later 5.x builds, and even a downloader that attempted persistence, Windows Defender and firewall bypasses, removable-drive propagation, and delivery of fresh payloads from hard-coded URLs. Researchers also documented repeated coding mistakes that enabled multiple public vaccines and decryptors, while defenders and projects such as No More Ransom helped victims recover files without paying in some cases.
The operation also fought an extended defensive battle with South Korean vendor AhnLab, repeatedly changing tactics to evade or disable V3 Lite, including uninstall automation, service termination, and code injection into Autoup.exe, while AhnLab and other vendors countered with kill switches, patches, and blocking methods. GandCrab’s operators announced they were shutting down after claiming enormous profits, but reporting and later law-enforcement action indicated the ecosystem did not simply disappear: a Belarusian affiliate was arrested for allegedly infecting more than 1,000 systems across nearly 100 countries, and researchers noted likely continuity between GandCrab personnel or code and later ransomware activity including REvil/Sodinokibi.

TTPs, infrastructure, and targeting history in one profile.
20 events from the most recent confirmed update back to the earliest known activity.
GandCrab ceased operations in mid-2019, with reporting indicating the shutdown took effect around the start of June and no new variants were observed afterward.
GandCrab's operators publicly announced they were shutting down the ransomware-as-a-service operation after claiming massive profits from the scheme.
Europol stated that more than 14,000 victims had recovered files using the newer GandCrab decryptor.
A decryptor released at the end of January 2019 led GandCrab's operators to respond with version 5.2, which changed encrypted file naming to random extensions.
GandCrab v5.0.4, observed in January 2019, moved away from uninstalling V3 Lite and instead attempted to stop the V3 service using dropped helper files and ASDCli.exe.
AhnLab added a CAPTCHA to the V3 Lite uninstall program to stop GandCrab from automating product removal.
A decryptor for GandCrab versions up to 5.03 was released through the No More Ransom platform, enabling victims to recover files without paying.
In September 2018, GandCrab updated its code to hide the V3 Lite uninstallation screen and automate button clicks without the user's knowledge.
In August 2018, the GandCrab creator told Bleeping Computer that an upcoming version would include a zero-day targeting AhnLab V3 Lite and shared exploit code.
GandCrab v4.1.2 was identified on July 17, 2018 after changing the .lock filename generation algorithm used in prior blocking methods and including a taunting message referencing Fortinet and AhnLab. AhnLab analyzed the modified routine and released an updated blocking tool that could still prevent encryption if the correct .lock file was created in the Common AppData path.
AhnLab released a public executable tool to block GandCrab after reverse engineering updated variants and their encryption logic.
Fortinet published a blocking method based on the presence of a .lock file in the Common AppData directory, and AhnLab confirmed it also worked against GandCrab v4.1.1.
By July 2018, GandCrab was being distributed through drive-by downloads, email, executable files, and fileless malware.
AhnLab released a public kill switch intended to prevent GandCrab from encrypting files on infected systems.
Version 2 of GandCrab appeared and fixed earlier implementation mistakes that had enabled prior free decryptors.
AhnLab reported active GandCrab distribution in South Korea, marking an early documented stage in the conflict between GandCrab and the vendor's V3 Lite product.
GandCrab first appeared in late January 2018 and went on to become a major ransomware-as-a-service threat through 2018 and the first half of 2019.
Belarusian authorities announced the arrest of a 31-year-old Gomel resident accused of acting as a GandCrab affiliate, infecting more than 1,000 computers across nearly 100 countries. Romanian and UK law enforcement assisted in identifying the suspect.
A newly released GandCrab-associated downloader was observed with anti-analysis features, removable-drive propagation, archive infection attempts, and hard-coded URLs used to fetch a new ransomware payload.
AhnLab released an emergency patch after GandCrab attack code targeting V3 Lite was revealed and shown capable of triggering a BSOD after encryption.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 16 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
10 references tracked. Mallory keeps watching after this page renders.
nomoreransom.org
Open sourcebleepingcomputer.com
Open sourcevirusbulletin.com
Open sourcevirusbulletin.com
Open sourcezdnet.com
Open sourcetccontre.blogspot.com
Open sourcebleepingcomputer.com
Open sourceasec.ahnlab.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.