Skip to content

GandCrab

GandCrab was a highly active Windows ransomware family and one of the defining ransomware-as-a-service operations of 2018 and 2019.

Profile source: Mallory opens in a new tab

GandCrab

Family profile

GandCrab was a highly active Windows ransomware family and one of the defining ransomware-as-a-service operations of 2018 and 2019. It was distributed through an affiliate model in which core operators supplied the malware and payment infrastructure while partners handled victim acquisition and deployment. Reported delivery methods included spam campaigns, exploit kits, and targeted intrusions against organizations, including attacks involving exposed services and compromised managed service environments. GandCrab was also delivered by other malware ecosystems and botnets, and it was used by multiple criminal affiliates rather than a single intrusion set.

On execution, GandCrab encrypted victim files and presented ransom instructions, with later variants evolving rapidly through frequent version updates. The family became notable for aggressive operator behavior, public taunting of defenders, and fast adaptation to defensive countermeasures. Some versions incorporated code intended to disrupt security software, including a retaliatory denial-of-service routine aimed at an AhnLab antivirus product. GandCrab’s operators also ran a mature revenue-sharing program and were widely cited as helping popularize the modern large-scale RaaS model later associated with successor operations.

The malware’s development history included multiple implementation flaws and infrastructure compromises that enabled the release of several public decryptors. Security vendors and law-enforcement partners repeatedly recovered or leveraged key material to support victim recovery for various versions. GandCrab was eventually announced as retired by its operators in 2019, after which REvil/Sodinokibi was widely assessed as a successor operation or continuation by overlapping actors and affiliates.

GandCrab primarily targeted Windows systems and affected a broad international victim base across consumer and enterprise environments. It was among the most prominent ransomware threats of its period due to its scale, affiliate ecosystem, rapid iteration, and influence on subsequent ransomware operations.

Capabilities

  • Defense Evasion
  • Extortion

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 27, 2026
Last activity
Sep 2, 2026
Feed role
C2 / Distribution
Host form
0 IP / 3 hostnames

Leading locations

  • US2

Leading providers

  • Amazon.com, Inc.1
  • Cloudflare, Inc.1

Infrastructure traits

  • Hosting 2
  • Anycast 1

Samples

Recent associated samples

Reported operators

Threat actors

6 named in public reporting
TA505

TA505 aurait pratiqué un usage ponctuel d’autres rançongiciels (Bart, Jaff, Scarab, Philadelphia, GlobeImposter et GandCrab).

G0092

For example, in 2017 TA505 (also known as G0092, GOLD TAHOE) began using GlobeImposter in replacement of Jaff, GandCrab, and Snatch to extend the reach and effectiveness of their campaigns.

lalartu

Lalartu (AKA Sheriff), a known persona in ransomware since 2019 who played a role in gangs such as GandCrab, REvil, Conti, and others, mentored Basstorlord.

Leafroller

Prior to its development of REvil, the group was associated with an older ransomware family known as Gandcrab.

Storm-0324

Storm-0324 has distributed a range of first-stage payloads since at least 2016, including: ... GandCrab ransomware

GOLD GARDEN

“…the operators of Gandcrab, GOLD GARDEN, retired and sold their operation to an affiliate group we now call GOLD SOUTHFIELD.”

Exploited software

Vulnerabilities linked to GandCrab

6 CVEs

MITRE ATT&CK

GandCrab in ATT&CK

72 distinct techniques

Techniques

72 techniques
T1059.005 Visual Basic T1497.003 Time Based Checks T1105 Ingress Tool Transfer T1071 Application Layer Protocol T1499 Endpoint Denial of Service T1486 Data Encrypted for Impact T1566 Phishing T1595 Active Scanning T1189 Drive-by Compromise T1203 Exploitation for Client Execution T1210 Exploitation of Remote Services T1078 Valid Accounts T1055 Process Injection T1021.001 Remote Desktop Protocol T1021 Remote Services T1199 Trusted Relationship T1027 Obfuscated Files or Information T1059.001 PowerShell T1059.003 Windows Command Shell T1134.001 Token Impersonation/Theft T1583 Acquire Infrastructure T1204 User Execution T1082 System Information Discovery T1489 Service Stop T1140 Deobfuscate/Decode Files or Information T1490 Inhibit System Recovery T1057 Process Discovery T1190 Exploit Public-Facing Application T1614.001 System Language Discovery T1491.001 Internal Defacement T1112 Modify Registry T1070.004 File Deletion T1068 Exploitation for Privilege Escalation T1204.002 Malicious File T1496 Resource Hijacking T1622 Debugger Evasion T1566.001 Spearphishing Attachment T1059 Command and Scripting Interpreter T1135 Network Share Discovery T1204.001 Malicious Link T1547.009 Shortcut Modification T1083 File and Directory Discovery T1070 Indicator Removal T1091 Replication Through Removable Media T1560 Archive Collected Data T1059.007 JavaScript T1564.001 Hidden Files and Directories T1036 Masquerading T1547.001 Registry Run Keys / Startup Folder T1497.001 System Checks T1480.002 Mutual Exclusion T1564.003 Hidden Window T1497 Virtualization/Sandbox Evasion T1562 Impair Defenses T1218 System Binary Proxy Execution T1218.010 Regsvr32 T1568 Dynamic Resolution T1665 Hide Infrastructure T1071.001 Web Protocols T1583.002 DNS Server T1583.003 Virtual Private Server T1583.004 Server T1568.001 Fast Flux DNS T1583.001 Domains T1090.003 Multi-hop Proxy T1620 Reflective Code Loading T1027.014 Polymorphic Code T1584 Compromise Infrastructure T1537 Transfer Data to Cloud Account T1657 Financial Theft T1567 Exfiltration Over Web Service T1041 Exfiltration Over C2 Channel

Reporting

Research mentioning GandCrab

May 7
Malpedia

Vidar (Malware Family)

Researchers and incident reports show the Vidar infostealer continuing to mature as a credential- and data-theft platform, with operators rotating backend infrastructure, tightening access to affiliate panels, and masking administration through Tor relays, VPN services, and hosting concentrated in Moldova and Russia. Team Cymru linked the operation to infrastructure including my-odin[.]com and several shifting IP addresses, while newer technical analysis found Vidar using multi-stage PowerShell delivery, process injection, API hooking, scheduled-task persistence, and theft of browser data by intercepting CryptProtectMemory before encryption. The malware targets Windows systems and steals credentials, cookies, autofill data, payment cards, crypto-wallet files, tokens, documents, and screenshots, then exfiltrates the data over encrypted channels. Campaigns tied to Vidar have used increasingly flexible command-and-control discovery and broad distribution channels. Analysts observed samples resolving C2 details dynamically through public profiles on Faceit, Telegram, and Steam, allowing operators to change infrastructure without rebuilding malware. Separate reporting tied Vidar to YouTube lures promoting cracked software and AI-generated tutorial videos, where victims were redirected to fake download sites that delivered stealer payloads. Earlier activity also showed Vidar deployed ahead of GandCrab ransomware, stealing victim data before downloading the encryptor, underscoring its role as both a standalone infostealer and a precursor for wider financially motivated intrusions.

Jan 1
Intezer

WatchBog: New BlueKeep Vulnerability Scanner & Linux Exploits - Intezer

Researchers reported that the WatchBog cryptomining botnet expanded its tooling beyond Linux-focused exploitation by adding a BlueKeep scanning module that probes RDP services on TCP 3389 for potentially vulnerable Windows hosts. The malware, active since at least 2018, primarily targets unpatched Linux systems and spreads through a Cython-compiled ELF implant that pulls command-and-control data from Pastebin, falls back to a hardcoded .onion service, and communicates over HTTPS without proper certificate validation. That TLS weakness allowed defenders to intercept tasking and victim telemetry, helping estimate roughly 4,500 infections tied to observed infrastructure, though the total may be higher. Across observed campaigns, WatchBog and related Linux miner activity exploited widely known flaws in Jira, Exim, Solr, Jenkins, Nexus Repository Manager 3, Confluence (CVE-2019-3396), and also abused CouchDB and Redis through brute-force or remote code execution. Once deployed, the operators installed XMRig or XMR-Stak Monero miners, established persistence with cron jobs, moved laterally over SSH using available keys and known_hosts, and in some cases used rootkits or Glibc-hooking libraries to hide processes, files, network traffic, and resource usage. Researchers said the activity underscores continued criminal exploitation of long-patched enterprise software vulnerabilities to build stealthy, self-propagating cryptomining botnets.

Aug 28
Aryaka

Vidar Infostealer in Action From API Hooking to Covert Data Exfiltration

Aug 25
Gatewatcher

Utilisation de faux profils Steam : Vidar Stealer prend les commandes - Gatewatcher

Jun 10
The Hacker News

More_eggs Malware Disguised as Resumes Targets Recruiters in Phishing Attack

Security firms reported multiple spearphishing campaigns that used LinkedIn job applications, fake job offers, and poisoned resumes to deliver the More_eggs malware to recruiters, hiring managers, and other business professionals. In observed intrusions, victims were directed through legitimate-looking resume workflows that ended with a malicious archive or shortcut file, often disguised as a document, which launched obfuscated activity and installed the JavaScript-based backdoor. The campaigns were seen across sectors including industrial services, aerospace and defense, legal, accounting, staffing, and healthcare technology, showing a sustained focus on personnel involved in recruiting and hiring. The malware and delivery chain were linked to Golden Chickens (also known as Venom Spider) and associated tooling such as VenomLNK, TerraLoader, and TerraPreter, though the specific operators behind individual incidents were not always confirmed. The attacks abused signed Windows binaries including regsvr32, wmic, msxsl.exe, ie4uinit.exe, and in earlier cases cmstp to evade detection, establish execution, perform discovery, and communicate with command-and-control infrastructure. Defenders said More_eggs can support credential theft, data exfiltration, lateral movement, remote access, and follow-on ransomware activity, and in at least one case endpoint telemetry caught suspicious XSL script processing and related malicious behavior before the intrusion succeeded.

May 2
Security Intelligence

Security | IBM

Nov 30
Medium G0njxa

Approaching stealers devs : a brief interview with Vidar | by g0njxa | Medium

Nov 22
Censys Other

Tracking Vidar Infrastructure with Censys - Censys

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.