GandCrab

Aliases: GrandCrab

Malware type
ransomware, exploit-kit
Family
Malware family
Last IoC activity
2026-07-22 01:55:25
Profile updated
2026-07-07 12:41:25

Targeted industries: financial-services healthcare-and-pharmaceutical retail-and-hospitality

Context

A new ransomware called GandCrab was released towards the end of last week that is currently being distributed via exploit kits. GandCrab has some interesting features not seen before in a ransomware, such as being the first to accept the DASH currency and the first to utilize the Namecoin powered .BIT tld.

Detection coverage

  • 2 YARA rules

Detection rules

  • CAPE_Gandcrab (yara-rule)
  • MALPEDIA_Win_Gandcrab_Auto (yara-rule)

Related threat objects

  • Fallout (infrastructure)

Reports & references

  • CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
  • CrowdStrike — Double Trouble Ransomware Data Leak Extortion Part 1 (report)
  • pwc.co.uk — Cyber Threats 2019 Retrospect (report)
  • CrowdStrike — Pinchy Spider Adopts Big Game Hunting (report)
  • secureworks.com — Gold Garden (report)
  • Microsoft — Human Operated Ransomware Attacks A Preventable Disaster (report)
  • CrowdStrike — The Evolution Of Revil Ransomware And Pinchy Spider (report)
  • bleepingcomputer.com — Gandcrab Ransomware Distributed By Exploit Kits Appends Gdcb Extension (report)
  • bleepingcomputer.com — Gandcrab Ransomware Being Distributed Via Malspam Disguised As Receipts (report)
  • bleepingcomputer.com — Gandcrab Ransomware Version 2 Released With New Crab Extension And Other Changes (report)
  • bleepingcomputer.com — Gandcrab Version 3 Released With Autorun Feature And Desktop Background (report)
  • bleepingcomputer.com — New Fallout Exploit Kit Drops Gandcrab Ransomware Or Redirects To Pups (report)
  • bleepingcomputer.com — Gandcrab V5 Ransomware Utilizing The Alpc Task Scheduler Exploit (report)
  • id-ransomware.blogspot.com — Gandcrab Ransomware (report)
  • ransomlook.io — Gandcrab (report)
  • bleepingcomputer.com — Gandcrab Ransomware Shuts Down After Claiming To Have Made Over 2 Billion (report)
  • Trend Micro — Uncovering The Evolution Of Gandcrab Ransomware (report)
  • CISA — Aa19 024A (report)
  • Kaspersky — 89631 (report)
  • Trend Micro — Global Operations Lead To Arrests Of Alleged Members Of Gandcrab (report)
  • blog.intel471.com — Revil Ransomware As A Service An Analysis Of A Ransomware Affiliate Operation (report)
  • jsac.jpcert.or.jp — Jsac2020 1 Tamada Yamazaki Nakatsuru En (report)
  • krebsonsecurity.com — Ransomware Gangs And The Name Game Distraction (report)
  • news.sophos.com — The Ransomware Threat Intelligence Center (report)
  • McAfee — Mcafee Atr Analyzes Sodinokibi Aka Revil Ransomware As A Service What The Code Tells Us (report)

External references