GandCrab
Aliases: GrandCrab
- Malware type
- ransomware, exploit-kit
- Family
- Malware family
- Last IoC activity
- 2026-07-22 01:55:25
- Profile updated
- 2026-07-07 12:41:25
Targeted industries: financial-services healthcare-and-pharmaceutical retail-and-hospitality
Context
A new ransomware called GandCrab was released towards the end of last week that is currently being distributed via exploit kits. GandCrab has some interesting features not seen before in a ransomware, such as being the first to accept the DASH currency and the first to utilize the Namecoin powered .BIT tld.
Detection coverage
- 2 YARA rules
Detection rules
- CAPE_Gandcrab (yara-rule)
- MALPEDIA_Win_Gandcrab_Auto (yara-rule)
Related threat objects
- Fallout (infrastructure)
Reports & references
- CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
- CrowdStrike — Double Trouble Ransomware Data Leak Extortion Part 1 (report)
- pwc.co.uk — Cyber Threats 2019 Retrospect (report)
- CrowdStrike — Pinchy Spider Adopts Big Game Hunting (report)
- secureworks.com — Gold Garden (report)
- Microsoft — Human Operated Ransomware Attacks A Preventable Disaster (report)
- CrowdStrike — The Evolution Of Revil Ransomware And Pinchy Spider (report)
- bleepingcomputer.com — Gandcrab Ransomware Distributed By Exploit Kits Appends Gdcb Extension (report)
- bleepingcomputer.com — Gandcrab Ransomware Being Distributed Via Malspam Disguised As Receipts (report)
- bleepingcomputer.com — Gandcrab Ransomware Version 2 Released With New Crab Extension And Other Changes (report)
- bleepingcomputer.com — Gandcrab Version 3 Released With Autorun Feature And Desktop Background (report)
- bleepingcomputer.com — New Fallout Exploit Kit Drops Gandcrab Ransomware Or Redirects To Pups (report)
- bleepingcomputer.com — Gandcrab V5 Ransomware Utilizing The Alpc Task Scheduler Exploit (report)
- id-ransomware.blogspot.com — Gandcrab Ransomware (report)
- ransomlook.io — Gandcrab (report)
- bleepingcomputer.com — Gandcrab Ransomware Shuts Down After Claiming To Have Made Over 2 Billion (report)
- Trend Micro — Uncovering The Evolution Of Gandcrab Ransomware (report)
- CISA — Aa19 024A (report)
- Kaspersky — 89631 (report)
- Trend Micro — Global Operations Lead To Arrests Of Alleged Members Of Gandcrab (report)
- blog.intel471.com — Revil Ransomware As A Service An Analysis Of A Ransomware Affiliate Operation (report)
- jsac.jpcert.or.jp — Jsac2020 1 Tamada Yamazaki Nakatsuru En (report)
- krebsonsecurity.com — Ransomware Gangs And The Name Game Distraction (report)
- news.sophos.com — The Ransomware Threat Intelligence Center (report)
- McAfee — Mcafee Atr Analyzes Sodinokibi Aka Revil Ransomware As A Service What The Code Tells Us (report)