Overview
Platforms:
—
Variants:
—
Extensions:
—
ATT&CK software:
—
Initial access:
Valid Accounts · Drive-by Compromise · Spearphishing Attachment
Top countries:
—
Observed sectors:
—
Attribution
PINCHY SPIDER
VERIFIED
Vendor tracking name
CrowdStrike tracks PINCHY SPIDER as the criminal group responsible for developing and operating the GandCrab ransomware ecosystem.
Affiliates
No affiliate information available.
Activity
Recent Observations
GandCrab announces retirement
June 2019
Operational closure
The operators announced the closure of the GandCrab ransomware-as-a-service program and instructed affiliates to stop distributing the ransomware.
More than 500,000 victims
February 2019
Ransomware activity
Europol reported that GandCrab had infected more than half a million victims since it was first detected.
Affiliates adopt big-game hunting
February 2019
Enterprise intrusion activity
GandCrab affiliates were observed conducting hands-on enterprise intrusions using stolen credentials, RDP and lateral movement techniques.
Major ransomware market share
August 2018
Ransomware activity
GandCrab grew rapidly through its affiliate model and was estimated to account for approximately half of the ransomware market.
TTPs
ATT&CK coverage:
6 techniques
· 5 tactics
T1078
Valid Accounts
VERIFIEDInitial Access / Persistence
GandCrab affiliates were observed using stolen credentials to access and move through enterprise environments.
T1021.001
Remote Desktop Protocol
VERIFIEDLateral Movement
GandCrab affiliates used RDP with compromised credentials to move laterally between systems.
T1562.001
Impair Defenses
VERIFIEDDefense Evasion
GandCrab affiliates were observed manually removing security software that prevented ransomware deployment.
Show more TTPs (3)
T1189
Drive-by Compromise
VERIFIEDInitial Access
GandCrab was distributed through exploit kits and malicious advertising delivered through compromised or malicious web infrastructure.
T1566.001
Spearphishing Attachment
VERIFIEDInitial Access
GandCrab was distributed through malicious email attachments presented as fictitious invoices.
T1486
Data Encrypted for Impact
VERIFIEDImpact
GandCrab encrypted victim files and demanded payment in exchange for decryption.
Victims
CVEs
No CVE associations available.
Infrastructure
GandCrab affiliate panel
GandCrab operated a ransomware-as-a-service partnership program that provided ransomware access to selected criminal affiliates in exchange for a share of ransom proceeds.
Payment infrastructure
GandCrab maintained payment and decryption infrastructure through which victims received ransom instructions and decryption material.
Timeline
2019-06
GandCrab announces retirement
The operators announced that the ransomware-as-a-service program was shutting down and affiliates were instructed to stop distribution.
2019-06
Universal decryptor released
Europol, law-enforcement partners and Bitdefender released a free decryptor covering GandCrab versions 1, 4 and 5 through 5.2.
2019-02
More than 500,000 victims
Europol reported that GandCrab had infected more than half a million victims worldwide.
Show more events (3)
2018-08
Dominant ransomware operation
GandCrab was estimated to account for roughly half of the ransomware market by August 2018.
2018-02
50,000 victims reported
Europol reported approximately 50,000 GandCrab victims within the first month of operation.
2018-01
GandCrab emerges
GandCrab appeared in January 2018 and began spreading through exploit kits and malicious campaigns.
Sources
PINCHY SPIDER Affiliates Adopt Big Game Hunting Tactics to Distribute GandCrab
CrowdStrike
Vendor research
Show more sources (5)
GandCrab ransomware distributed by RIG and GrandSoft exploit kits
Malwarebytes Labs