German authorities have revealed the true identity of the mysterious hacker who went by the alias UNKN and ran two of the most destructive Russian ransomware in recent years. 31-year-old Russian Daniil Maksimovich Shchukin is believed to have been the mastermind behind the GandCrab and REvil, which blackmailed victims around the world and extorted millions in ransom. The revelation of UNKN is a significant step in the international effort to combat organized cybercrime.

According to a statement from Germany's Federal Criminal Police (BKA), Shchukin and his partner, 43-year-old Anatoly Sergeevitsch Kravchuk, carried out at least 130 cyber sabotage and extortion activities against German organizations between 2019 and 2021.The two Russians managed to extort almost 2 million euros through 24 cyber attacks, causing total financial damage exceeding 35 million euros. The investigation by German authorities revealed that the attacks mainly targeted medium-sized and large companies, with a particular emphasis on organizations that handle sensitive data.
The GandCrab group first emerged in January 2018 as one of the first ransomware-as-a-service (RaaS) platforms . This model allowed other criminals to use the malware in exchange for a share of the profits, while the creators handled the negotiations and delivery of the decryption keys. The group pioneered the tactic of double extortion , charging victims both for the decryption key and for not disclosing stolen data. This innovative approach dramatically increased the criminals’ profits and became the model for future ransomware groups .
See also: Russian court sentences four members of REvil Ransomware gang
The evolution from GandCrab to REvil and the action of UNKN
On May 31, 2019 , the GandCrab group announced its closure, claiming to have stolen more than $2 billion from victims. “ We are proof that you can do evil and get away with it ,” the group’s farewell message read . Almost simultaneously with the end of GandCrab , the REvil group emerged under the leadership of UNKN , with many cybersecurity experts believing it to be a reorganization of the same criminal organization. The transition from GandCrab to REvil was not just a name change, but a strategic evolution that included improved encryption techniques and more sophisticated methods of penetrating corporate networks.
UNKN made a splash on Russian cybercrime forums when he posted $ 1 million as bail to prove his serious intentions. In an interview with Recorded Future , he described his life story and how he went from poverty to riches: “ As a child, I would scavenge through trash and smoke cigarette butts. I would walk 10 kilometers to school. I wore the same clothes for six months. When I was little, I wouldn’t eat for two or three days. Now I’m a millionaire .” This narrative reveals the motivations behind his turn to cybercrime and partly explains his ruthless approach to business practices.

Shchukin 's name appeared in a US Department of Justice court document in February 2023. Authorities were seeking the seizure of crypto accounts linked to REvil 's activity . The digital wallet associated with Shchukin contained more than $317,000 in illicit cryptocurrency. US authorities systematically monitored the group's transactions, creating a digital footprint that eventually led to the identification of key members.
See also: Hackers trick victims into installing Red Ransomware
As described in the book The Ransomware Hunting Team by Renee Dudley and Daniel Golden, UNKNOWN and REvil reinvested significant profits into improving their success and copying the practices of legitimate businesses. The authors wrote:
“Just as a real manufacturer might hire other companies to handle logistics or website design, ransomware developers increasingly outsourced tasks beyond their scope, focusing on improving the quality of their ransomware. Higher-quality ransomware – which, in many cases, Hunting Team could not eliminate – resulted in more and higher payouts from victims. The huge payouts allowed the gangs to reinvest in their businesses. They hired more specialists, and their success accelerated.”
Criminals rushed to join the booming ransomware economy. Underworld support service providers sprang up or diverted from other criminal activities to meet developers’ demand for personalized support. Partnering with gangs like GandCrab, “crypto” providers ensured that ransomware could not be detected by standard anti-malware scanners. “Early access brokers” specialized in stealing credentials and finding vulnerabilities in target networks, selling that access to ransomware operators and collaborators. Bitcoin “tumblers” offered discounts to gangs that used them as a preferred supplier for laundering money from ransom payments. Some contractors were open to working with any gang, while others struck exclusive partnerships.
The REvil group evolved into a formidable "big game hunting" machine capable of extracting exorbitant sums from victims, largely targeting organizations with annual revenues in excess of $100 million.

According to Krebs on Security, the July 2021 attack on Kaseya was particularly significant , where REvil targeted the cloud-based MSP platform and demanded $70 million in Bitcoin to decrypt all affected systems. The attack affected more than 1,500 people and 1,000 businesses worldwide. This attack proved to be a catalyst for international cooperation against ransomware groups , as the scale and scope of the impact was unprecedented.
See also: Google Drive: AI ransomware detection for all subscribers
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Technical methods and protection strategies
German investigations revealed that the two Russians used advanced OSINT (open-source intelligence) to determine which companies to target and how much ransom to demand. Their methodology included detailed analysis of the targets’ financial statements, assessing the criticality of their systems, and estimating the likelihood of payment. Organizations can protect themselves by implementing multi-factor authentication, network segmentation to limit attackers’ lateral movement, and regular backups (offline storage). In addition, employee training on phishing and social engineering is critical, as these are the main methods of initial penetration.
REvil 's infrastructure was eventually dismantled as a result of an international law enforcement operation, with Reuters reporting that the group's infrastructure was "captured" by authorities . The revelation of the identity of UNKN and its associates marks a new phase in the fight against organized cybercrime, proving that even the most sophisticated criminals cannot hide forever behind pseudonyms and encrypted communications. International cooperation and persistent monitoring of digital footprints are proving to be effective tools in the fight against ransomware .
Source: krebsonsecurity.com
