GandCrab: The Ransomware That Turned Extortion Into a Subscription Business

Key takeaways
- GandCrab launched in January 2018 as ransomware-as-a-service: its creators rented the malware to affiliates and took a cut of each ransom, with operators later claiming more than $2 billion in payments over 18 months, though researchers said that figure was inflated.
- McAfee found GandCrab’s affiliate program ran like a sales operation: top performers kept up to 70% of ransom payments, payouts were made in Dash, low-performing affiliates were expelled, and the malware was coded to avoid Russia and other former Soviet states.
- The malware combined AES and RSA encryption, deleted Windows shadow copies, and decrypted one file for free to prove it worked; it also offered dark-web victim support around the clock, making the extortion process feel like a customer-service transaction.
- Bitdefender, Europol, Romanian police, and law enforcement in France, the UK, and Bulgaria released three free decryptors in 2018-2019; the February 2019 tool for version 5.1 helped unlock more than 30,000 computers and deny an estimated $50 million to the operators.
- After the February 2019 decryptor, GandCrab’s share of tracked ransomware infections fell from roughly half of all cases to less than a third within a month, showing how free recovery tools can push victims not to pay and affiliates to abandon an unreliable product.
- GandCrab’s operators announced retirement on June 3, 2019, but weeks later REvil/Sodinokibi appeared with code Sophos said was nearly identical, including debug paths labeled 'gcfin' and version numbering tied to GandCrab, suggesting the 'retirement' was effectively a rebrand.
How a criminal affiliate program modeled itself on customer service, and how a run of free decryption tools helped force its early retirement.
An Adaptive Security series on the ransomware attacks that shaped modern cyber defense. Hub: A History of Notable Ransomware Attacks. Previously: WannaCry.
GandCrab arrived in January 2018 with a business plan behind the code. Its creators built the software, then rented it out to anyone willing to spread it, keeping a cut of every ransom that came in. That single decision turned ransomware from a one-group operation into an open marketplace. Within eighteen months, GandCrab’s operators claimed to have collected more than $2 billion in payments before shutting the operation down. Researchers who tracked the campaign called that figure inflated. Even a fraction of it would have made GandCrab one of the most profitable criminal operations of its time.
GPcode had proven the encryption could work. Cryptorbit had proven the con could be cheap. WannaCry had proven the spread could be fast. GandCrab proved something else: the entire operation could be sold as a service to anyone willing to run it.
A Ransomware Kit With a Sales Pitch
Researchers at McAfee, who studied GandCrab’s affiliate program in depth, found the developers ran it with the same discipline as a legitimate sales operation. Partners kept a majority of every ransom, up to 70 percent for top earners, paid out in Dash, a cryptocurrency built around private transactions. Underperforming affiliates were expelled outright, the same way a sales team might cut low performers rather than carry them. New partners were accepted based on one thing only: the infected traffic they could reliably deliver, whether through spam campaigns, malicious ads, or exploit kits already planted on compromised websites. Which countries the malware infected was decided somewhere else entirely, in the code itself, not in who got hired as an affiliate. GandCrab was coded to avoid infecting Russia and other former Soviet states, the same territory researchers believe its creators called home.
The software came ready for a mass market. It encrypted files with a combination of AES and RSA cryptography, deleted the backup copies Windows keeps for exactly this kind of emergency, and unlocked one file for free so victims could confirm the process worked before they paid for the rest. A support channel on the dark web answered questions around the clock, often from the same victims who had refused to pay a few hours earlier. The experience was built to feel less like an attack and more like a transaction, complete with customer service.
The Response That Worked
Fighting GandCrab took the same kind of coordination its creators used to build it. Bitdefender worked with Europol, Romanian police, and law enforcement in France, the United Kingdom, and Bulgaria to release three free decryption tools between 2018 and 2019. The most important one arrived in February 2019, targeting version 5.1. Together, those three releases unlocked more than 30,000 computers and kept an estimated $50 million out of the operators’ hands. Within a month of the February release, GandCrab’s share of ransomware infections tracked by researchers fell from roughly half of all cases to less than a third. That drop reflected two decisions happening at once: victims refusing to pay, and affiliates walking away from a product that free decryption tools kept making worthless.
Lillian Ablon, a researcher who has studied cybercrime markets at the RAND Corporation, has pointed to why damaging a product's reputation inside a criminal marketplace works as a strategy. "Reducing confidence within black markets, that's the goal," she said. "Everyone is confident that the products work, that people are who they say they are, and that there's little risk of getting caught. To disrupt, maybe combine coordinated takedowns with blasting a ton of bad data, bad products, and false users into these markets to start to diminish confidence." Free decryption tools did something close to that for GandCrab. Every unlock was proof to the affiliates spreading it that the software they depended on might fail for nothing.
The Retirement That Wasn’t
GandCrab’s operators announced their retirement on June 3, 2019, writing that they had “successfully cashed this money and legalized it in various spheres of white business, both in real life and on the internet.” “We are leaving for a well-deserved retirement,” one operator wrote, adding that they had “proved that in a year you can earn money for a lifetime.” They told affiliates to stop distributing the ransomware within 20 days and warned that decryption keys for anyone who had not yet paid would be deleted by the end of the month.
The retirement did not last. Weeks later, a new strain called REvil, also known as Sodinokibi, appeared with code almost identical to GandCrab’s, down to the method it used to build the web addresses malware uses to reach its operators and the way it hid text inside the program. Researchers at Sophos found debug file paths inside REvil’s code labeled gcfin, which they read as shorthand for GandCrab Final, along with a version number that matched GandCrab’s internal numbering instead of REvil’s own. The retirement looked less like an exit and more like a rebrand.
What the Franchise Model Left Behind
Whether or not the same people built REvil, the business structure behind GandCrab survived its own retirement. Renting out ransomware meant recruiting far more people into the job of infecting a victim’s computer, each one paid only when that infection succeeded. Affiliates spread it through spam email, including messages disguised as CDC flu alerts, along with malicious ads and exploit kits planted on hacked websites. By 2019, some had switched to a simpler method: guessing weak passwords on exposed remote-desktop connections until one worked.
Every one of those entry points depended on the same thing: a person clicking, or a password nobody had bothered to strengthen. Adaptive Security studies this history because a criminal marketplace this size grows by recruiting more people willing to open one more message or reuse one more weak password, the same opening security awareness training exists to close.
Next in this series: Coca-Cola, where this history meets a household name for the first time.
Get started with Adaptive Security
Get started