Description Summary
GandCrab was one of the first ransomware families to fully embrace the ransomware-as-a-service model, active from January 2018 until an announced retirement in June 2019. Its developers claimed affiliates extorted over USD 2 billion. Affiliates could customize file extensions, ransom-note text, and demands. After retirement, strong code and infrastructure overlaps link GandCrab's operators to the subsequent REvil/Sodinokibi operation. Free decryptors were released via the No More Ransom project.
Threat Actor
RaaS operators (Russian-speaking); assessed to have relaunched as REvil/Sodinokibi. Distributed via exploit kits, spam, and RDP.
Technical Indicators
Encryption Extension
.GDCB / .CRAB / .KRAB / random 5–10 char
Encryption Algorithm
Salsa20 (files) + RSA-2048 (key wrapping); early versions used AES
Ransom Note Name
GDCB-DECRYPT.txt / KRAB-DECRYPT.txt / [random]-DECRYPT.txt
Targeted Industries
Cross-sector (SMB-heavy), Healthcare, Retail
First Seen
January 2018
Last Seen
June 2019 (retired; No More Ransom decryptors released)
Geographical Location
Worldwide
MITRE ATT&CK Matrix
| Tactic | TTP | Technique Name |
|---|---|---|
| Initial Access x 3 | T1566 | Phishing |
| T1189 | Drive-by Compromise (exploit kits) | |
| T1190 | Exploit Public-Facing Application | |
| Execution x 1 | T1059.001 | PowerShell |
| Defense Evasion x 1 | T1027 | Obfuscated Files or Information |
| Impact x 2 | T1486 | Data Encrypted for Impact |
| T1490 | Inhibit System Recovery |