Overview

Platforms: —
Variants: —
Extensions: —
ATT&CK software: —
Initial access: Valid Accounts · Drive-by Compromise · Spearphishing Attachment
Top countries: —
Observed sectors: —

Attribution

PINCHY SPIDER VERIFIED
Vendor tracking name
CrowdStrike tracks PINCHY SPIDER as the criminal group responsible for developing and operating the GandCrab ransomware ecosystem.

Affiliates

No affiliate information available.

Activity

Recent Observations

GandCrab announces retirement
June 2019
Operational closure
The operators announced the closure of the GandCrab ransomware-as-a-service program and instructed affiliates to stop distributing the ransomware.
More than 500,000 victims
February 2019
Ransomware activity
Europol reported that GandCrab had infected more than half a million victims since it was first detected.
Affiliates adopt big-game hunting
February 2019
Enterprise intrusion activity
GandCrab affiliates were observed conducting hands-on enterprise intrusions using stolen credentials, RDP and lateral movement techniques.
Major ransomware market share
August 2018
Ransomware activity
GandCrab grew rapidly through its affiliate model and was estimated to account for approximately half of the ransomware market.

TTPs

ATT&CK coverage: 6 techniques · 5 tactics
T1078 Valid Accounts
VERIFIED
Initial Access / Persistence
GandCrab affiliates were observed using stolen credentials to access and move through enterprise environments.
T1021.001 Remote Desktop Protocol
VERIFIED
Lateral Movement
GandCrab affiliates used RDP with compromised credentials to move laterally between systems.
T1562.001 Impair Defenses
VERIFIED
Defense Evasion
GandCrab affiliates were observed manually removing security software that prevented ransomware deployment.
Show more TTPs (3)
T1189 Drive-by Compromise
VERIFIED
Initial Access
GandCrab was distributed through exploit kits and malicious advertising delivered through compromised or malicious web infrastructure.
T1566.001 Spearphishing Attachment
VERIFIED
Initial Access
GandCrab was distributed through malicious email attachments presented as fictitious invoices.
T1486 Data Encrypted for Impact
VERIFIED
Impact
GandCrab encrypted victim files and demanded payment in exchange for decryption.

Victims

CVEs

No CVE associations available.

Infrastructure

GandCrab affiliate panel
GandCrab operated a ransomware-as-a-service partnership program that provided ransomware access to selected criminal affiliates in exchange for a share of ransom proceeds.
Payment infrastructure
GandCrab maintained payment and decryption infrastructure through which victims received ransom instructions and decryption material.

Timeline

2019-06
GandCrab announces retirement
The operators announced that the ransomware-as-a-service program was shutting down and affiliates were instructed to stop distribution.
2019-06
Universal decryptor released
Europol, law-enforcement partners and Bitdefender released a free decryptor covering GandCrab versions 1, 4 and 5 through 5.2.
2019-02
More than 500,000 victims
Europol reported that GandCrab had infected more than half a million victims worldwide.
Show more events (3)
2018-08
Dominant ransomware operation
GandCrab was estimated to account for roughly half of the ransomware market by August 2018.
2018-02
50,000 victims reported
Europol reported approximately 50,000 GandCrab victims within the first month of operation.
2018-01
GandCrab emerges
GandCrab appeared in January 2018 and began spreading through exploit kits and malicious campaigns.

Sources