Skip to main content
Rethinking Email Security for the AI Era, August 25th
Blog
Email Security

GandCrab Ransomware: Timeline, Versions, Decryption, and Attribution

AUGUST 24, 202624 MIN READ
Adaptive TeamAdaptive Team
Chat with a real personno Slack required
GandCrab Ransomware: Timeline, Versions, Decryption, and Attribution

Key takeaways

  • GandCrab ransomware operated as a ransomware-as-a-service family from January 2018 until its operators announced a shutdown on May 31, 2019, and the original infrastructure has been dead since.
  • A free GandCrab decryption tool exists through the No More Ransom portal for versions 1, 4, and 5.0.1 through 5.2, and no free tool has ever been released for versions 2 and 3.
  • The operators claimed enormous revenue on retirement, and no independent measurement of GandCrab ransomware earnings has ever been published by any reliable source.
  • GandCrab ransomware encrypted files without stealing or publishing them, which distinguishes it from the double-extortion model its successor strain later defined.
  • Germany's Federal Criminal Police publicly named two alleged leaders of the GandCrab ransomware and REvil ransomware operation in April 2026, and both are believed to be in Russia and remain at large.
  • Researchers concluded that GandCrab ransomware's developers rebranded as REvil ransomware, also known as Sodinokibi, weeks before the retirement announcement.
  • Detections labeled GandCrab ransomware still surface in 2026 telemetry, largely because antivirus engines apply the label to unrelated commodity ransomware reusing techniques GandCrab popularized.

GandCrab ransomware was a ransomware-as-a-service family first detected in January 2018 that encrypted Windows files and demanded payment in Dash cryptocurrency. Its operators announced a shutdown on May 31, 2019. Free decryption tools cover most versions, and in April 2026 Germany's Federal Criminal Police publicly named two alleged leaders of the operation.

GandCrab ransomware shutdown in 2019 still generates recovery inquiries despite free decryptors available for most versions

A ransomware family whose operators walked away on May 31, 2019 still generates search demand from organizations holding files encrypted years earlier. GandCrab ransomware left an unusual footprint behind it, including four separate free decryptor releases and an operator group that stayed unnamed for almost seven years.

This detailed record of GandCrab ransomware’s even history explains:

  • How the GandCrab ransomware affiliate model split revenue, and why several published accounts state the split backwards;
  • Which versions a free GandCrab decryption tool covers, including GandCrab 5.2, and which two versions it has never covered;
  • What the confirmed victim record shows, and what the operators claimed that nobody has ever verified;
  • How the GandCrab ransomware operators became REvil ransomware, and what Germany's April 2026 attribution established;
  • Why detections labeled GandCrab ransomware still appear in 2026 cyber threat telemetry.

Ransomware families disappear while the human behaviors that let them in persist across every successor strain. Adaptive Security builds the recognition and reporting habits that shorten cyberattacker dwell time.

Explore the platform

GandCrab Ransomware Quick Facts and Confidence Ratings

The reference table below condenses the established record on GandCrab ransomware into the attributes that matter most for version identification, file recovery, and attribution of the operation. Each row carries a confidence rating drawn from the underlying sourcing, which separates facts established by law enforcement and regulators from assertions the operators made about themselves and never substantiated.

Attribute Detail Confidence
Name GandCrab CONFIRMED
Type Ransomware-as-a-service family CONFIRMED
First detected January 2018, cited as January 26 to 28 CONFIRMED
Shutdown announced May 31, 2019, on the Exploit.in forum CONFIRMED
Operators Russian-speaking; representative UNKN; developer group tracked as GOLD GARDEN CONFIRMED (behavior); REPORTED (named individuals)
Affiliate split Affiliates kept 60 to 70% CONFIRMED
Encryption RSA plus AES-256-CBC (v1 to v3); Salsa20 with RSA-2048 (v4 and v5) CONFIRMED
File extensions .GDCB (v1), .CRAB (v2 and v3), .KRAB (v4), randomized 5 to 10 characters (v5) CONFIRMED
Ransom notes GDCB-DECRYPT.txt, CRAB-DECRYPT.txt, KRAB-DECRYPT.txt, [extension]-DECRYPT.txt or .html CONFIRMED
Ransom currency Dash, later optionally Bitcoin at a premium CONFIRMED
Extortion model Single extortion, encryption only, no leak site CONFIRMED
Victim scale Over 1.5 million machines estimated CONFIRMED as estimate
Aggregate ransoms paid Never independently measured UNKNOWN
Free decryptor Versions 1, 4, and 5.0.1 to 5.2; not v2 or v3 CONFIRMED
Successor REvil, also known as Sodinokibi CONFIRMED (code link); INFERRED (same operators)
Attribution BKA advisory, April 5, 2026 CONFIRMED (advisory); REPORTED (culpability)

What GandCrab Ransomware Was and How Its Affiliate Model Worked

GandCrab ransomware ran as a service business rather than 9 a single malware sample, and that commercial structure explains its 2018 dominance better than its encryption does. A core development team built and maintained the code while recruited affiliates carried out the intrusions themselves. The revenue split between those two groups is stated backwards on several widely read pages, which makes the commercial mechanics worth setting out precisely.

GandCrab Ransomware as a Ransomware-as-a-Service Business

Ransomware-as-a-service describes an arrangement in which one group builds and maintains the malware and a separate pool of affiliates carries out intrusions in exchange for a share of each payment. The GandCrab ransomware core team ran the payment portal, the version releases, and the affiliate program, while affiliates chose targets and delivery methods independently.

Recruitment ran openly on the Russian-language cybercrime forums Exploit.in and XSS. According to BBC News's Notorious GandCrab Hacker Group 'Returns From Retirement' (2019), GandCrab ransomware is estimated to have affected more than 1.5 million machines.

That reach came from delegation. One development team supported hundreds of independent distributors, so the strain scaled faster than operator-run families that depended on a single crew, a pattern shared across other ransomware attack types and how they operate.

How GandCrab Ransomware Affiliates Were Paid

Affiliates kept 60 to 70% of every ransom paid, and the GandCrab ransomware developers retained the remainder. The recruitment advertisement quoted by Krebs on Security in July 2019 promised that "Each affiliate is guaranteed USD 10,000" and set the starting affiliate share at 60%.

Several published accounts invert this arrangement and describe affiliates receiving 30 to 40%. The inverted figure appears on more pages than the correct one, so the confirmed GandCrab ransomware split favored the affiliate instead of the developer.

Why GandCrab Ransomware Avoided CIS Countries

The GandCrab ransomware payload refused to run on systems showing Russian and other Commonwealth of Independent States keyboard and language settings, with Syria added to the exclusion list later. That behavior supports the assessment that the operators were Russian-speaking and locally exposed to prosecution. It does not establish where any individual operator physically resided.

Affiliate crews scale intrusions faster than most security teams scale defensive readiness across a workforce. Adaptive Security delivers role-relevant cybersecurity awareness training that closes that readiness gap.

Book a demo

GandCrab Ransomware Timeline: January 2018 to the 2026 Attribution

GandCrab ransomware was first detected January 2018 not 2017 so incident reporting should verify date sources before publication

The GandCrab ransomware story runs seven years past the shutdown announcement, and the arc is defined by the exchange between law enforcement decryptor releases and the operator response to each one. NHS England Digital publishes January 2017 as the first-observed date, which is incorrect. The strain was first detected in January 2018, with sources citing January 26 to 28 and no day-level resolution available.

GandCrab Ransomware Timeline Table

Date Event Source Confidence
April 1, 2017 Initial access to Doctors' Management Services via exposed RDP HHS OCR CONFIRMED
January 2018 (c. 26 to 28) First detected, advertised as ransomware-as-a-service Europol CONFIRMED
February 2018 First decryptor (v1), with Romanian Police, DIICOT, Europol Europol CONFIRMED
Late February 2018 About 50,000 victims in under a month Europol CONFIRMED
July 2018 v4 released; Salsa20, .KRAB No More Ransom CONFIRMED
October 2018 Second decryptor (v1, 4, 5 to 5.0.3) Europol CONFIRMED
December 24, 2018 Doctors' Management Services detects compromise HHS OCR CONFIRMED
February 19, 2019 Decryptor for v5.0.4 to 5.1 Europol CONFIRMED
April 17, 2019 REvil first seen; GandCrab also dropped via CVE-2019-2725 Cisco Talos CONFIRMED
April 22, 2019 Doctors' Management Services discloses by breach report to HHS HHS OCR CONFIRMED
May 31, 2019 Retirement announced, with a claim of $2 billion extorted Krebs on Security CONFIRMED (post); CLAIMED (figure)
June 2019 Final decryptor (v1, 4, 5.0.1 to 5.2) Europol CONFIRMED
July 2019 FBI Flash Alert releases master keys, v4 to 5.2 FBI alert via BleepingComputer CONFIRMED
July 30, 2020 Belarus arrests a 31-year-old affiliate in Gomel Belarus Ministry of Internal Affairs CONFIRMED
February 25, 2021 South Korea arrests a 20-year-old affiliate The Record CONFIRMED
August 3, 2021 FBI seizes 39.89138522 BTC from affiliate Lalartu Forfeiture complaint via BleepingComputer CONFIRMED
November 4, 2021 Operation GoldDust: Kuwait arrests a GandCrab affiliate, Romania two REvil affiliates Europol CONFIRMED
October 31, 2023 HHS OCR announces first ransomware HIPAA settlement with Doctors' Management Services HHS OCR CONFIRMED
April 5, 2026 BKA names Shchukin and Kravchuk, both wanted internationally, believed in Russia BKA; Krebs on Security CONFIRMED (advisory); REPORTED (guilt)

How Each Decryptor Release Shaped the GandCrab Ransomware Campaign

Four free decryptor releases landed across sixteen months: in February 2018, October 2018, February 2019, and June 2019. The operators answered each release with a new version, which is visible in Europol's announcement of the universal decryption tool. Europol observed that the pattern encouraged victims of GandCrab ransomware to wait for a tool instead of paying the ransom.

How a GandCrab Ransomware Attack Worked, Stage by Stage

No single GandCrab ransomware attack chain existed, because each affiliate selected its own access method and delivery infrastructure. That variability is precisely what made the strain difficult to characterize defensively, since two victims of the same malware could have been reached by entirely different routes. The stages below describe behavior at a level security teams can act on.

How GandCrab Ransomware Got In: Exploit Kits, Malspam, and RDP

Affiliates delivered a GandCrab ransomware attack through exploit kits including RIG, GrandSoft, Fallout, and Magnitude, distributed by malvertising and compromised websites. Malicious spam carried weaponized Office documents, JavaScript, and VBScript attachments, including volumes pushed through the Necurs spam infrastructure.

Fake software cracks and brute-forced or credential-based Remote Desktop Protocol access supplied the remaining confirmed routes. In April 2019, affiliates weaponized Oracle WebLogic CVE-2019-2725 within days of disclosure, documented in Oracle's security alert for CVE-2019-2725, alongside compromise of remote management software used by managed service providers.

According to VirusTotal's Ransomware in a Global Context 2021, GandCrab was present in about 78.5% of ransomware samples submitted between January 2020 and August 2021, a share of submitted samples across a window that postdates the shutdown in preference to a measure of live victims, and 95% of ransomware files analyzed were Windows executables or dynamic link libraries.

How GandCrab Ransomware Spread Across a Network

Once running, the payload scanned local drives and removable media and enumerated network shares, extending beyond mapped drives alone. Later versions could complete encryption without contacting a command and control server, which removed the network callback that defenders often relied on for detection.

Enterprise affiliates behaved differently from the mass-distribution crews. They authenticated with stolen domain credentials, ran the GandCrab ransomware attack manually, and directed it across the network from a compromised host. According to Verizon's Data Breach Investigations Report 2026, stolen credentials account for 13% of breaches, which is the same access class those affiliates exploited.

What Happened After GandCrab Ransomware Encrypted the Files?

The ransom note directed victims to a Tor payment portal that offered one free test decryption and continuous chat support. A GandCrab ransomware attack ended at that point, with no exfiltration stage.

Stop treating malicious attachments and fake update prompts as problems that technical controls alone resolve. Adaptive Security runs phishing simulation programs built on the lure patterns cyberattackers actually deploy.

Take a self-guided tour

GandCrab Ransomware Versions, File Extensions, and Encryption

GandCrab ransomware version identification depends on file extension and ransom-note filename to match recovery tools by variant

Version identification is the first practical step for anyone holding files encrypted by GandCrab ransomware, because whether a free recovery tool exists is determined entirely by which version ran. The appended file extension and the ransom-note filename together form the identifying pair. The reference below covers every release from the January 2018 version through GandCrab 5.2.

GandCrab Ransomware Version and Extension Reference

Version Extension appended Encryption Ransom note Free decryptor Confidence
v1 .GDCB RSA plus AES-256-CBC GDCB-DECRYPT.txt Yes CONFIRMED
v2 .CRAB RSA plus AES-256-CBC CRAB-DECRYPT.txt No CONFIRMED
v3 .CRAB RSA plus AES-256-CBC CRAB-DECRYPT.txt No CONFIRMED
v4 .KRAB Salsa20 with RSA-2048 KRAB-DECRYPT.txt Yes CONFIRMED
v5 to v5.2 Randomized 5 to 10 characters Salsa20 with RSA-2048 [extension]-DECRYPT.txt or .html Yes, 5.0.1 to 5.2 CONFIRMED

Version 5 appended a randomized extension of 5 to 10 characters, so no specific example extension identifies it. The No More Ransom decryptor documentation records the mapping for every covered release.

What Encryption GandCrab Ransomware Used

GandCrab ransomware versions 1 through 3 used RSA together with AES-256-CBC. Versions 4 and 5, including GandCrab 5.2, switched to the Salsa20 stream cipher with RSA-2048 protecting the keys.

The switch matters for recoverability. Free tools exist for the Salsa20 generations because law enforcement and researchers obtained key material for them, while two of the earlier AES-based versions were never covered.

How Victims Identify Which GandCrab Ransomware Version Encrypted Their Files

The appended extension and the ransom-note filename identify the version together. The ransom note must be preserved, since it carries the key material that recovery depends on.

How Many Victims GandCrab Ransomware Had and What Its Operators Claimed

Two very different classes of number attach to GandCrab ransomware, and conflating them is the most common error in existing coverage. Victim counts come from law enforcement and represent cumulative snapshots taken at different dates. Revenue figures come only from the operators, and no independent party has ever checked any of them.

The Confirmed GandCrab Ransomware Victim Count

According to Europol's press release Free Data Recovery Kit for Victims of GandCrab Ransomware Now Available on No More Ransom (2018), GandCrab ransomware made over 50,000 victims in less than one month, with ransoms of "USD 300-500 in the DASH virtual currency".

Business victims concentrated in India, the United States, Ukraine, the United Kingdom, Germany, France, and Italy, with healthcare, manufacturing, and professional services prominent.

According to Europol's press release Pay No More: Universal GandCrab Decryption Tool Released for Free on No More Ransom (2019), GandCrab ransomware infected over 500,000 victims from January 2018 onward. These totals count infected devices rather than distinct organizations, and each is a snapshot at its publication date.

What the GandCrab Ransomware Operators Claimed on Retirement

The GandCrab ransomware operators asserted a revenue figure in the retirement post published on Exploit.in on May 31, 2019. Four inconsistent variants circulated, and that inconsistency is itself evidence.

Claimed by the GandCrab ransomware operators Established by the public record Confidence
More than $2 billion extorted in aggregate No independent measurement of aggregate revenue has been published CLAIMED
About $2.5 million weekly and about $150 million personally Europol characterized global losses as hundreds of millions of dollars CLAIMED
Over $150 million per year, in later retellings The variants conflict with each other and with the aggregate figure CLAIMED

The same operators embedded the names of security publications and projects in their command infrastructure, which bears on the weight their financial assertions carry.

Why GandCrab Ransomware Revenue Has Never Been Independently Measured

No Chainalysis edition published between 2020 and 2026 carries a GandCrab ransomware revenue estimate. Dash is not cryptographically untraceable, so the barrier is analytical attention rather than cryptography. The defensible anchors are Europol's qualitative losses characterization and the unpaid-ransom figure.

Cyberattacker claims travel further than verified figures, and unverified numbers distort how organizations rank their own exposure. Adaptive Security grounds risk decisions in measured workforce behavior rather than assertion.

Explore the platform

Who Was Behind GandCrab Ransomware and What the 2026 Attribution Established

Operator identity stayed an open question for seven years after the GandCrab ransomware shutdown, and every arrest announced before 2026 caught an affiliate rather than a developer. Germany's Federal Criminal Police changed the state of the record on April 5, 2026 by naming two men it alleges led the operation. That advisory is an allegation untested in court, and it did not change the practical odds of a trial.

The GandCrab Ransomware Operators Before They Were Named

The developer group behind GandCrab ransomware is tracked as GOLD GARDEN under one vendor tracking convention, with the public representative using the handle UNKN, also rendered as UNKNOWN. The operators were Russian-speaking, avoided Commonwealth of Independent States targets, and recruited on Exploit.in and XSS.

Identity stayed unresolved through 2025 despite heavy coverage of GandCrab ransomware, because forum handles alone rarely support a named identification.

Germany's April 2026 GandCrab Ransomware Attribution

According to the BKA advisory of April 5, 2026, reported by Krebs on Security's reporting on the attribution, Daniil Maksimovich Shchukin, 31, of Krasnodar is the man alleged to have used the handle UNKN. The advisory also names Anatoly Sergeevitsch Kravchuk, 43, born in Makiivka, Ukraine, as the alleged developer of the malware and the extortion management site.

The BKA alleges both men headed the combined GandCrab ransomware and REvil operation from at least early 2019 until at least July 2021. It links them to 130 cyberattacks in Germany, 25 paid ransoms totaling about 1.9 million euros, and more than 35.4 million euros in damage.

Both men were added to the EU Most Wanted portal alongside a public appeal for information. A February 2023 United States Department of Justice filing independently linked Shchukin to a cryptocurrency wallet holding over $317,000.

Krebs on Security noted that the Ger0in handle connected to Shchukin was active only in 2010 and 2011, years before UNKNOWN appeared, which leaves a documented gap in the alias chain.

Why No GandCrab Ransomware Developer Has Been Arrested

Every publicized arrest connected to GandCrab ransomware caught an affiliate. Key law enforcement actions occurred in Belarus (July 2020), South Korea (throughout 2021), and Kuwait and Romania under Operation GoldDust (November 2021). Similarly, unsealed 2021 Department of Justice indictments focused on REvil affiliates instead of GandCrab’s primary creators.

Both alleged leaders are believed to be in Russia, which does not extradite its citizens, so enforcement now runs through asset seizure and travel restriction. According to the FBI Internet Crime Complaint Center's Internet Crime Report 2025, reported cybercrime losses reached $20.877 billion, a 26% increase, which frames how little of that total any single prosecution recovers.

What the Doctors' Management Services Case Shows About GandCrab Ransomware in Enterprises

GandCrab ransomware encrypted without exfiltration while REvil added double extortion later so successor behavior should not redefine earlier operations

GandCrab ransomware is remembered as a consumer-scale strain, and almost no enterprise victim ever disclosed publicly. One regulator-confirmed case therefore constitutes the entire documented enterprise record. Doctors' Management Services, a Massachusetts medical billing and payer-credentialing company and HIPAA business associate, is worth reading closely for that reason.

How GandCrab Ransomware Reached Doctors' Management Services

Unauthorized access to the Doctors' Management Services network began on April 1, 2017 through an exposed Remote Desktop Protocol workstation. The organization did not detect the compromise until December 24, 2018, when GandCrab ransomware encrypted files on its network server.

That sequence implies roughly 20 months between initial access and detection, an inference drawn from the two regulator-confirmed dates. Doctors' Management Services filed a breach report on April 22, 2019.

According to the United States Department of Health and Human Services Office for Civil Rights announcement HHS' Office for Civil Rights Settles Ransomware Cyber-Attack Investigation With Doctors' Management Services (2023), the breach affected 206,695 individuals and was resolved for $100,000, as recorded in the HHS Office for Civil Rights settlement announcement.

What Data the GandCrab Ransomware Incident Exposed

The regulator framed the incident as potential exposure of protected health information. The categories included names, addresses, dates of birth, Social Security numbers, driver's license numbers, insurance details, Medicare and Medicaid identifiers, and diagnostic information.

No evidence of publication exists, which is consistent with the single-extortion behavior GandCrab ransomware displayed everywhere else. According to IBM's Cost of a Data Breach Report 2026, the global average cost of a data breach reached $4.99 million, which indicates the financial weight a record exposure of this size now carries.

Why Refusing to Pay Did Not Prevent a Penalty

Doctors' Management Services declined to pay and restored from backup, so the GandCrab ransomware extortion attempt failed outright. A HIPAA penalty followed regardless, with the Office for Civil Rights citing failures in risk analysis, system activity monitoring, and Security Rule policies. It remains the first ransomware-related HIPAA settlement on record.

Twenty months of undetected access turned one exposed workstation into a reportable breach affecting hundreds of thousands. Adaptive Security shortens detection intervals through trained escalation behavior across the workforce.

Book a demo

What GandCrab Ransomware Stole and What It Did Not

GandCrab ransomware predated the leak-site era and encrypted files without exfiltrating them in its own operations. Recent coverage has begun retrojecting double extortion onto the strain because of how its successor behaved after 2019. The BKA advisory of April 5, 2026 describes the combined GandCrab and REvil operation, and that description fits the REvil period.

GandCrab Ransomware Used Single Extortion Only

The GandCrab ransomware operators ran no leak site, published no victim data, and made no per-victim theft claims of the kind that became standard from late 2019 onward. Their claimed column is limited to aggregate financial bragging about revenue.

For victims, that model had one practical consequence: a tested backup ended the incident completely, because nothing had been taken. According to Verizon's Data Breach Investigations Report 2026, ransomware is present in 48% of breaches, and most of those incidents now carry an exfiltration component GandCrab ransomware never had.

The Vidar Infostealer Pairing and Its Limits

Some campaigns paired GandCrab ransomware with the Vidar infostealer, a credential-harvesting malware family, which is reported in preference to confirmed. That pairing was affiliate-level tooling and never a capability of the ransomware itself.

The distinction matters when assessing historical exposure, because credential theft creates downstream fraud risk that encryption alone does not. According to the FBI Internet Crime Complaint Center's Internet Crime Report 2025, business email compromise losses reached $3.046 billion, which is the category harvested credentials most often feed.

How the GandCrab Decryption Tool Works and Which Versions It Covers

Free recovery is available for most versions of GandCrab ransomware, and it is available through one legitimate route. A GandCrab decryption tool covers versions 1, 4, and 5.0.1 through 5.2, which includes GandCrab 5.2. Two versions have never been covered, and no page should describe them as recoverable without backups.

Where to Get a Legitimate GandCrab Decryption Tool

The single legitimate route to a GandCrab decryption tool is the No More Ransom portal, a project of Europol and the Dutch National Police. The tools themselves were produced by the Romanian Police under General Prosecutor's Office supervision, working with Bitdefender.

The FBI released master decryption keys for versions 4 through 5.2 in July 2019, which extended coverage further. Before running anything, the encrypted files and the ransom note must be preserved, since the note carries key material a GandCrab decryption tool depends on.

Which GandCrab Ransomware Versions Have a Free Decryption Tool

Versions 1, 4, and 5.0.1 through 5.2 are covered by a free GandCrab decryption tool. Versions 2 and 3 have never had one, and both appended the .CRAB extension, so extension alone does not settle whether recovery is possible.

According to Europol figures reported by SecurityWeek in Decryptor Released for Latest GandCrab Ransomware Variants (2019), earlier decryptors helped over 30,000 victims recover data, representing roughly $50 million in unpaid ransoms.

Organizations encrypted by versions 2 or 3 have two realistic options: restore from backup, or accept the loss. No GandCrab decryption tool has ever covered those releases.

What to Do If No GandCrab Decryption Tool Covers the Files

Preserve the encrypted files and the ransom note in preference to deleting them, since coverage has expanded before. The FBI, Europol, and INTERPOL advise against paying, a position examined further in this comparison of REvil ransomware and the Kaseya supply chain incident.

Recovery tools arrive too late for organizations without tested backups or a workforce that reports suspicious messages early. Adaptive Security converts reported emails into measurable readiness signals for security teams.

Take a self-guided tour

Is GandCrab Ransomware Still Active, and What Replaced It

GandCrab ransomware operation ended in 2019 but detection tools still emit the label so 2026 telemetry requires operational context not labels

The GandCrab ransomware operation is defunct, and the code lineage it produced is not. Those two facts are conflated constantly, because detection tooling continues to emit the GandCrab label years after the infrastructure went dark. Separating the operation from the label is the only way to read 2026 telemetry correctly.

GandCrab Ransomware Is Defunct as an Operation

The GandCrab ransomware operation ceased in June 2019, and master decryption keys were released the following month. The original payment infrastructure is dead and no affiliate program has operated under the name since.

Both alleged leaders have now been named by Germany's Federal Criminal Police, and both remain at large. Nothing in the 2026 attribution indicates a revived GandCrab ransomware operation.

How GandCrab Ransomware Became REvil

REvil ransomware, also known as Sodinokibi, was first seen on April 17, 2019, weeks before the retirement announcement. MITRE ATT&CK's entry for REvil records the code similarity between the two families, and the Department of Health and Human Services Health Sector Cybersecurity Coordination Center describes REvil ransomware as a continuation of GandCrab ransomware.

Debug paths recovered from early REvil builds referenced GandCrab naming conventions, which supports the succession argument on technical grounds. The code link is confirmed, while the conclusion that the same people ran both operations is an inference from that evidence.

Researchers have separately linked REvil ransomware to DarkSide and BlackMatter, which is reported in preference to confirmed. A distinct group tracked as GOLD NORTHFIELD repurposed the compiled REvil binary through configuration patching in June 2021, which is code reuse without operator continuity.

Why GandCrab Ransomware Detections Still Appear in 2026

Antivirus engines apply the GandCrab ransomware label to unrelated commodity ransomware that reuses techniques the strain popularized, which VirusTotal identified as the cause of persistent detections. The original distribution footprint was broad enough to keep legacy samples circulating in submission datasets. Persistent detections do not indicate an active operation.

Defunct operations leave behind reusable techniques that successor crews deploy against the same untrained employees. Adaptive Security keeps cybersecurity awareness training aligned to techniques currently in circulation.

Explore the platform

Defensive Lessons From the GandCrab Ransomware Campaign

The useful lessons from GandCrab ransomware come from one documented enterprise intrusion and from the decryptor record, in preference to from the malware itself. The controls that decided outcomes were unglamorous ones: access hygiene, monitoring, and tested backups. According to Verizon's Data Breach Investigations Report 2026, 62% of breaches involving the human element are non-malicious, which describes the error class the campaign exploited most often.

What the GandCrab Ransomware Intrusion Record Shows About Access Controls

Exposed Remote Desktop Protocol was the documented enterprise entry point in the only GandCrab ransomware case a regulator has examined. Multi-factor authentication and restricted remote access were absent at Doctors' Management Services, and the Office for Civil Rights cited that gap directly.

The detection gap converted an intrusion into a reportable breach. Encryption fired 20 months after access, which was the first signal anyone acted on. Least privilege on domain credentials matters equally, because enterprise affiliates propagated GandCrab ransomware manually using accounts they had already stolen.

What GandCrab Ransomware Showed About Backups and Human Factors

Tested offline backups defeated single extortion in the one documented enterprise case, since Doctors' Management Services restored without paying. At consumer and small-business scale the dominant delivery routes for GandCrab ransomware were human-triggered: malicious spam attachments, fake update prompts, and pirated software installers.

Affiliates also ran their own social engineering campaigns. One prosecuted South Korean affiliate sent 6,486 phishing emails demanding roughly $1,300 each while impersonating police. According to the FBI Internet Crime Complaint Center's Internet Crime Report 2025, phishing and spoofing generated 191,561 complaints, which keeps that delivery route the most reported one. Continuous phishing simulation programs address exactly this behavior class.

Why Waiting Beat Paying Against GandCrab Ransomware

Four free decryptor releases across sixteen months let many victims of GandCrab ransomware recover without paying, and Europol observed that this encouraged a wait-for-a-tool posture. According to Chainalysis's The 2026 Crypto Crime Report, total on-chain ransomware payments fell approximately 8% to $820 million in 2025 while claimed cyberattacks rose 50%, and the median ransom payment grew 368% year over year to nearly $60,000.

Backups and patch discipline fail when nobody reports the message that started the intrusion in the first hour. Adaptive Security makes reporting the fastest path available to every employee.

Book a demo

How Adaptive Security Addresses the Human Factors Behind GandCrab Ransomware Style Cyberattacks

Adaptive Security addresses GandCrab-era delivery through phishing simulations matching actual lure patterns and reporting workflows shortening analyst response time

The GandCrab ransomware record shows that its dominant delivery routes at consumer and small-business scale were human-triggered, including malicious spam attachments, fake update prompts, and pirated software installers. Adaptive Security answers that exposure with phishing simulation content modeled on the lure patterns campaigns actually use, role-relevant cybersecurity awareness training for staff holding domain credentials, and reporting workflows that shorten the interval between a suspicious message arriving and a security team seeing it.

The cybersecurity awareness training platform records reporting rates and susceptibility by role, so security leaders can see where exposure concentrates instead of counting completion rate. The documented enterprise case points at the other half of the problem: an exposed RDP workstation.

No awareness program would have blocked that entry, and the roughly 20-month gap before detection was a monitoring and reporting failure. Adaptive Security contributes there by making escalation routine, so staff know what counts as an anomaly worth raising and exactly who receives it. Detection in weeks instead of months changes the regulatory and operational consequences of an identical intrusion.

Generic annual modules leave employees rehearsing scenarios no ransomware affiliate has used since 2019. Adaptive Security delivers cybersecurity awareness training and phishing simulation content matched to current cyberattacker tradecraft.

Take a self-guided tour

Frequently Asked Questions About GandCrab Ransomware

What Encryption Does GandCrab Ransomware Use?

GandCrab ransomware used RSA together with AES-256-CBC in versions 1 through 3, then switched to the Salsa20 stream cipher with RSA-2048 protecting the keys in versions 4 and 5. That change determines which releases have a free decryption tool, because key material was recovered for the Salsa20 generations and for version 1 only.

Is There a Free GandCrab Decryption Tool for Every Version?

No. A free GandCrab decryption tool covers versions 1, 4, and 5.0.1 through 5.2 through the No More Ransom portal, and versions 2 and 3 have never been covered. Both uncovered versions append the .CRAB extension, so victims of those releases depend on restoring from backup.

Is GandCrab Ransomware Still Active?

No. The GandCrab ransomware operation ceased in June 2019 after its operators announced a shutdown on May 31, 2019, and the original infrastructure is dead. Detections carrying the GandCrab label still appear in 2026 because antivirus engines apply it to unrelated commodity ransomware that reuses techniques the strain popularized.

Who Was Behind GandCrab Ransomware?

Germany's Federal Criminal Police named Daniil Maksimovich Shchukin and Anatoly Sergeevitsch Kravchuk as the alleged leaders of the combined GandCrab and REvil operation in an advisory published on April 5, 2026. Both men are wanted internationally, are believed to be in Russia, and the allegations remain untested in court.

Did the GandCrab Ransomware Operators Really Earn $2 Billion?

The figure is a claim made by the GandCrab ransomware operators in their retirement post of May 31, 2019, and no independent measurement of the operation's revenue has ever been published. Four inconsistent variants of the claim circulated, and no Chainalysis edition from 2020 through 2026 carries a GandCrab-specific estimate.

Is REvil the Same Group as GandCrab Ransomware?

REvil ransomware, also known as Sodinokibi, appeared on April 17, 2019 and shares documented code similarity with GandCrab ransomware, recorded by MITRE ATT&CK, and the Department of Health and Human Services describes REvil as a continuation. The conclusion that the same people ran both operations remains an inference from that technical evidence.

What Does GandCrab Ransomware Do to Encrypted Files?

GandCrab ransomware encrypted files on local drives, removable media, and network shares, appended a version-specific extension, and dropped a ransom note directing victims to a Tor payment portal. It did not steal or publish files, so encrypted data was rendered unusable without ever leaving the network.

How Do Victims Identify Which GandCrab Ransomware Version Infected Them?

The appended file extension and the ransom-note filename identify the version together: .GDCB with GDCB-DECRYPT.txt for version 1, .CRAB with CRAB-DECRYPT.txt for versions 2 and 3, .KRAB with KRAB-DECRYPT.txt for version 4, and a randomized extension for version 5. The ransom note must be preserved.

Questions about a defunct ransomware family end; questions about workforce readiness do not, because every successor strain reuses the same delivery habits. Adaptive Security answers the second question.

Book a demo

Adaptive Team

Adaptive Team

As experts in cybersecurity insights and AI threat analysis, the Adaptive Security Team is sharing its expertise with organizations.

Get started with Adaptive Security

Get started

Human security for the AI era.