GandCrab, a new ransomware-as-a-service emerges from Russian crime underground

Discussion in 'malware problems & news' started by Minimalist, Feb 4, 2018.

  1. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    https://securityaffairs.co/wordpress/68636/malware/gandcrab-raas.html
     
  2. cruelsister

    cruelsister Registered Member

    Joined:
    Nov 6, 2007
    Posts:
    1,649
    Location:
    Paris
    The crab has actually been out for a while now and pushed by various kits. Nothing really special (my cat is rather dismissive of it...).
     
  3. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    https://www.theregister.co.uk/2018/02/28/gandcrab_decryptor/
     
  4. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    4,653
    Europol Press Release - 28 Feb 2018
    "Free data recovery kit for victims of GandCrab ransomware now available on No More Ransom"
    https://www.europol.europa.eu/newsr...dcrab-ransomware-now-available-no-more-ransom

    The Bitdefender site: https://labs.bitdefender.com/tag/decryption-tool/

    For the No More Ransom project see:
    https://www.nomoreransom.org/en/index.html
    https://www.wilderssecurity.com/thr...anies-join-forces-to-fight-ransomware.387365/
     
  5. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    EITest HoeflerText Scam Distributing GandCrab & Netsupport Manager
    https://www.bleepingcomputer.com/ne...distributing-gandcrab-and-netsupport-manager/

     
  6. guest

    guest Guest

    Compile Error Halts Some GandCrab Ransomware Infections
    April 13, 2018
    https://www.bleepingcomputer.com/ne...or-halts-some-gandcrab-ransomware-infections/
     
  7. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    A bug in GandCrab ransomware V3 accidentally locks systems running Windows 7
    https://securityaffairs.co/wordpress/72142/cyber-crime/gandcrab-ransomware.html
     
  8. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    GandCrab ransomware attacks from legitimate websites
    https://www.2-spyware.com/gandcrab-ransomware-attacks-from-legitimate-websites
     
  9. guest

    guest Guest

    GandCrab V4 Released With the New .KRAB Extension for Encrypted Files
    July 3, 2018
    https://www.bleepingcomputer.com/ne...h-the-new-krab-extension-for-encrypted-files/
     
  10. guest

    guest Guest

    Microsoft might not support Windows XP any more, but GandCrab v4.1 ransomware does
    July 9, 2018
    https://www.theregister.co.uk/2018/07/09/legacy_windows_ransomware/
     
  11. guest

    guest Guest

    No Evidence of GandCrab Leveraging SMB Exploit – Yet
    July 16, 2018
    https://threatpost.com/no-evidence-of-gandcrab-leveraging-smb-exploit-yet/134017/
     
  12. guest

    guest Guest

    Vaccine Available for GandCrab Ransomware v4.1.2
    July 19, 2018
    https://www.bleepingcomputer.com/news/security/vaccine-available-for-gandcrab-ransomware-v412/
     
  13. guest

    guest Guest

    GandCrab Ransomware Author Bitter After Security Vendor Releases Vaccine App
    August 03, 2018
    https://www.bleepingcomputer.com/ne...r-after-security-vendor-releases-vaccine-app/
     
  14. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
  15. guest

    guest Guest

    GandCrab’s Rotten EGGs Hatch Ransomware in South Korea
    August 20, 2018
    https://threatpost.com/gandcrabs-rotten-eggs-hatch-ransomware-in-south-korea/136689/
     
  16. guest

    guest Guest

    New Fallout Exploit Kit Drops GandCrab Ransomware or Redirects to PUPs
    September 6, 2018
    https://www.bleepingcomputer.com/ne...ops-gandcrab-ransomware-or-redirects-to-pups/
     
  17. guest

    guest Guest

    New GandCrab variant attacks Florida School District
    September 14, 2018
    https://www.scmagazine.com/home/news/new-gandcrab-variant-attacks-florida-school-district/
     
  18. guest

    guest Guest

    GandCrab V5 Released With Random Extensions and New HTML Ransom Note
    September 25, 2018
    https://www.bleepingcomputer.com/ne...h-random-extensions-and-new-html-ransom-note/
     
  19. guest

    guest Guest

    GandCrab v5 Ransomware Utilizing the ALPC Task Scheduler Exploit
    September 26, 2018
    https://www.bleepingcomputer.com/ne...re-utilizing-the-alpc-task-scheduler-exploit/
     
  20. guest

    guest Guest

    Phorpiex worm pivots to infect the enterprise with GandCrab ransomware
    September 27, 2018
    https://www.zdnet.com/article/phorp...prise-with-ransomware-through-weak-endpoints/
     
  21. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    4,653
    Several Dutch news sites are reporting today about a rise in GanCrab infections with thousands computers infected.
    I'm really sorry, those sites are in Dutch.
    https://www.rtlnieuws.nl/tech/artikel/4432861/duizenden-ransomware-slachtoffers-gandcrab
    https://nos.nl/artikel/2252585-nieuwe-ransomware-gijzelt-duizenden-nederlandse-computers.html

    According to the articles there are many computers infected in Holland, Germany, Belgium, UK.

    The articles have quotes from:
    Thomas Maarseveen of Steel Mountain;
    Dave Maasland of ESET NL;
    Maarten van Dantzig of Fox-IT.
     
  22. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    My guess is its attacking devices that haven't applied this month's cumulative Win update related to the above ALPC Task Scheduler Exploit vulnerability.
     
  23. guest

    guest Guest

    Z-LAB Report – Analyzing the GandCrab v5 ransomware
    October 3, 2018
    https://securityaffairs.co/wordpress/76763/malware/gandcrab-v5-ransomware.html
    full ZLAB Malware Analysis Report (PDF): http://csecybsec.com/download/zlab/20181001_CSE_GandCrabv5.pdf
     
  24. guest

    guest Guest

    Rapidly Evolving Ransomware GandCrab Version 5 Partners With Crypter Service for Obfuscation
    October 10, 2018
    https://securingtomorrow.mcafee.com...artners-with-crypter-service-for-obfuscation/
     
  25. guest

    guest Guest

    GandCrab Devs Release Decryption Keys for Syrian Victims
    October 17, 2018
    https://www.bleepingcomputer.com/ne...s-release-decryption-keys-for-syrian-victims/
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.