Last seven days
- First activity
- Aug 27, 2026
- Last activity
- Sep 2, 2026
- Feed role
- C2 / Distribution
- Host form
- 0 IP / 3 hostnames
GandCrab was a highly active Windows ransomware family and one of the defining ransomware-as-a-service operations of 2018 and 2019.
Profile source: Mallory opens in a new tabGandCrab
GandCrab was a highly active Windows ransomware family and one of the defining ransomware-as-a-service operations of 2018 and 2019. It was distributed through an affiliate model in which core operators supplied the malware and payment infrastructure while partners handled victim acquisition and deployment. Reported delivery methods included spam campaigns, exploit kits, and targeted intrusions against organizations, including attacks involving exposed services and compromised managed service environments. GandCrab was also delivered by other malware ecosystems and botnets, and it was used by multiple criminal affiliates rather than a single intrusion set.
On execution, GandCrab encrypted victim files and presented ransom instructions, with later variants evolving rapidly through frequent version updates. The family became notable for aggressive operator behavior, public taunting of defenders, and fast adaptation to defensive countermeasures. Some versions incorporated code intended to disrupt security software, including a retaliatory denial-of-service routine aimed at an AhnLab antivirus product. GandCrab’s operators also ran a mature revenue-sharing program and were widely cited as helping popularize the modern large-scale RaaS model later associated with successor operations.
The malware’s development history included multiple implementation flaws and infrastructure compromises that enabled the release of several public decryptors. Security vendors and law-enforcement partners repeatedly recovered or leveraged key material to support victim recovery for various versions. GandCrab was eventually announced as retired by its operators in 2019, after which REvil/Sodinokibi was widely assessed as a successor operation or continuation by overlapping actors and affiliates.
GandCrab primarily targeted Windows systems and affected a broad international victim base across consumer and enterprise environments. It was among the most prominent ransomware threats of its period due to its scale, affiliate ecosystem, rapid iteration, and influence on subsequent ransomware operations.
C2 tracking
Derp observations, rolling seven-day window
Samples
047e138efd0c8dbb52cc949ad66ffc45f4a64eeecd7d35fc2fa473495785fb1a 5760bf3dfa834dd40a2d43d948d7bb617014f6fd324bd8be6701e91f9176921f 6acc0714d3cbab8c42b03d03044f0c56134ed9a651bd1f7a88d8c8f56c978f6a 8684751f02d87ad7979218ee32929bd7d1dbad5f22dd78016f4d9d9144662ece 94ef48cdfeaf9733cab63ef0b640c506856ed636da5c6760ed6727a005657b19 022472ef0bbcdea73d9a28e7cf9dea4b3e620f15f195629af596ad8a65e4e70c 1830dc42b6f639b1f341f8c344a08addff33879b0fa9eae7876e3105a8472a17 915589eee5bd2bcd2c863dfba09907a72015a94991bce0e7c9cfd0783b6f5317 b7fe404126cef6f6e543f4892a6bdb70c590dfb5bde46fa506eb57c6a4ca3a53 f78723728aad0dd0c7cb32039c2c48b6bf0ce19df5c7b92a9298767472884962 Reported operators
TA505 aurait pratiqué un usage ponctuel d’autres rançongiciels (Bart, Jaff, Scarab, Philadelphia, GlobeImposter et GandCrab).
For example, in 2017 TA505 (also known as G0092, GOLD TAHOE) began using GlobeImposter in replacement of Jaff, GandCrab, and Snatch to extend the reach and effectiveness of their campaigns.
Lalartu (AKA Sheriff), a known persona in ransomware since 2019 who played a role in gangs such as GandCrab, REvil, Conti, and others, mentored Basstorlord.
Prior to its development of REvil, the group was associated with an older ransomware family known as Gandcrab.
Storm-0324 has distributed a range of first-stage payloads since at least 2016, including: ... GandCrab ransomware
“…the operators of Gandcrab, GOLD GARDEN, retired and sold their operation to an affiliate group we now call GOLD SOUTHFIELD.”
Exploited software
MITRE ATT&CK
Reporting
Researchers and incident reports show the Vidar infostealer continuing to mature as a credential- and data-theft platform, with operators rotating backend infrastructure, tightening access to affiliate panels, and masking administration through Tor relays, VPN services, and hosting concentrated in Moldova and Russia. Team Cymru linked the operation to infrastructure including my-odin[.]com and several shifting IP addresses, while newer technical analysis found Vidar using multi-stage PowerShell delivery, process injection, API hooking, scheduled-task persistence, and theft of browser data by intercepting CryptProtectMemory before encryption. The malware targets Windows systems and steals credentials, cookies, autofill data, payment cards, crypto-wallet files, tokens, documents, and screenshots, then exfiltrates the data over encrypted channels. Campaigns tied to Vidar have used increasingly flexible command-and-control discovery and broad distribution channels. Analysts observed samples resolving C2 details dynamically through public profiles on Faceit, Telegram, and Steam, allowing operators to change infrastructure without rebuilding malware. Separate reporting tied Vidar to YouTube lures promoting cracked software and AI-generated tutorial videos, where victims were redirected to fake download sites that delivered stealer payloads. Earlier activity also showed Vidar deployed ahead of GandCrab ransomware, stealing victim data before downloading the encryptor, underscoring its role as both a standalone infostealer and a precursor for wider financially motivated intrusions.
Researchers reported that the WatchBog cryptomining botnet expanded its tooling beyond Linux-focused exploitation by adding a BlueKeep scanning module that probes RDP services on TCP 3389 for potentially vulnerable Windows hosts. The malware, active since at least 2018, primarily targets unpatched Linux systems and spreads through a Cython-compiled ELF implant that pulls command-and-control data from Pastebin, falls back to a hardcoded .onion service, and communicates over HTTPS without proper certificate validation. That TLS weakness allowed defenders to intercept tasking and victim telemetry, helping estimate roughly 4,500 infections tied to observed infrastructure, though the total may be higher. Across observed campaigns, WatchBog and related Linux miner activity exploited widely known flaws in Jira, Exim, Solr, Jenkins, Nexus Repository Manager 3, Confluence (CVE-2019-3396), and also abused CouchDB and Redis through brute-force or remote code execution. Once deployed, the operators installed XMRig or XMR-Stak Monero miners, established persistence with cron jobs, moved laterally over SSH using available keys and known_hosts, and in some cases used rootkits or Glibc-hooking libraries to hide processes, files, network traffic, and resource usage. Researchers said the activity underscores continued criminal exploitation of long-patched enterprise software vulnerabilities to build stealthy, self-propagating cryptomining botnets.
Security firms reported multiple spearphishing campaigns that used LinkedIn job applications, fake job offers, and poisoned resumes to deliver the More_eggs malware to recruiters, hiring managers, and other business professionals. In observed intrusions, victims were directed through legitimate-looking resume workflows that ended with a malicious archive or shortcut file, often disguised as a document, which launched obfuscated activity and installed the JavaScript-based backdoor. The campaigns were seen across sectors including industrial services, aerospace and defense, legal, accounting, staffing, and healthcare technology, showing a sustained focus on personnel involved in recruiting and hiring. The malware and delivery chain were linked to Golden Chickens (also known as Venom Spider) and associated tooling such as VenomLNK, TerraLoader, and TerraPreter, though the specific operators behind individual incidents were not always confirmed. The attacks abused signed Windows binaries including regsvr32, wmic, msxsl.exe, ie4uinit.exe, and in earlier cases cmstp to evade detection, establish execution, perform discovery, and communicate with command-and-control infrastructure. Defenders said More_eggs can support credential theft, data exfiltration, lateral movement, remote access, and follow-on ransomware activity, and in at least one case endpoint telemetry caught suspicious XSL script processing and related malicious behavior before the intrusion succeeded.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.