HomeSecurityGandCrab Ransomware Wasn't Retired Like We Thought

GandCrab Ransomware Wasn't Retired Like We Thought

GandCrab Ransomware Wasn't Retired Like We Thought

The creators of the infamous GandCrab ransomware, who tried to mislead users over the summer that they had been removed, now appear to be back, after SecureWorks discovered a new ransomware strain linked to them.

In June, the developers behind the GandCrab ransomware said they planned to retire after amassing a whopping $2 billion in ransom.

According to Bitdefender, GandCrab was first released in January 2018 and managed to become the most common strain globally, to the point where it accounted for 50% of all ransomware attacks.

The creators of GandCrab

Despite the malware developers ' statements , SecureWorks researchers warn that criminals may not have given up, after discovering a new ransomware strain.

GandCrab had spread like wildfire, thanks in part to its sales technique, which allowed criminals to buy ready-made kits in exchange for returning 40% of their proceeds to the developers.

However, SecureWorks said it had detected REVIL (also known as Sodinokibi) in April of this year.

“Analysis by Secureworks’ Corporate Threat Unit (CTU) suggests that REvil is likely related to the GandCrab ransomware, due to similar code and the appearance of REvil just as GandCrab activity began to decline,” the researchers state.

“Given the diverse and advanced delivery mechanisms, code complexity, and resources used by REvil, CTU researchers estimate that this ransomware will replace GandCrab as a widespread threat,” the researchers warned. “REvil does not contain worm-like features that would allow it to spread laterally during an infection. It would need to be installed or downloaded via malware that has this capability.”

“The best way to limit the damage from ransomware is to back up your valuable data,” they added. “CTU researchers recommend that organizations use a 3-2-1 backup strategy to ensure successful data recovery in the event of attack .”

Don Smith, director of Secureworks' Threat Response Unit, told the BBC:

“We are not surprised that the group has resurfaced. GandCrab offered good rewards to criminals. It is unlikely that an existing and capable group would stop its activities. It is possible that they wanted to reduce the attention that GandCrab had attracted so that they could start over with a new product,” he concluded.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS