GandCrab Ransomware

Description Summary

GandCrab was one of the first ransomware families to fully embrace the ransomware-as-a-service model, active from January 2018 until an announced retirement in June 2019. Its developers claimed affiliates extorted over USD 2 billion. Affiliates could customize file extensions, ransom-note text, and demands. After retirement, strong code and infrastructure overlaps link GandCrab's operators to the subsequent REvil/Sodinokibi operation. Free decryptors were released via the No More Ransom project.

Threat Actor

RaaS operators (Russian-speaking); assessed to have relaunched as REvil/Sodinokibi. Distributed via exploit kits, spam, and RDP.

Technical Indicators

Encryption Extension
.GDCB / .CRAB / .KRAB / random 5–10 char
Encryption Algorithm
Salsa20 (files) + RSA-2048 (key wrapping); early versions used AES
Ransom Note Name
GDCB-DECRYPT.txt / KRAB-DECRYPT.txt / [random]-DECRYPT.txt
Targeted Industries
Cross-sector (SMB-heavy), Healthcare, Retail
First Seen
January 2018
Last Seen
June 2019 (retired; No More Ransom decryptors released)
Geographical Location
Worldwide

MITRE ATT&CK Matrix

Tactic TTP Technique Name
Initial Access x 3 T1566 Phishing
T1189 Drive-by Compromise (exploit kits)
T1190 Exploit Public-Facing Application
Execution x 1 T1059.001 PowerShell
Defense Evasion x 1 T1027 Obfuscated Files or Information
Impact x 2 T1486 Data Encrypted for Impact
T1490 Inhibit System Recovery