• Cyber Security
    • Ransomware Prevention
    • Ransomware Removal
    • Ransomware File Recovery
    • Ransomware Types
  • Ransomware Services
    • Ransomware Removal
    • Ransomware File Recovery
  • News
  • Tutorials
  • Ransomware TV

Decryption tool for some Gandcrab variants is now available

November 23, 2018Simeon Georgiev

Gandcrab ransomware has been inflicting cryptovirological attacks since January 2017. In this time period, many variants of this ransomware family have been developed. There is good news for all those users who have lost their data to the encryption activity of Gandcrab. According to the latest reports, the cybercrime division of Europol has come up with a ransomware removal solution for all the users affected by Gandcrab.

Cyber experts from the United Kingdom, Netherlands, Romania, Bulgaria, France, Poland, and Italy have teamed up to develop a ransomware removal measure against encryption activity of Gandcrab. However, it is important to mention here that the developed decryption tool won’t be effective against the activity of Gandcrab v5 and v1.4. Affected users have to consult professional ransomware removal experts if they are targeted by the aforementioned Gandcrab variants.

A short profile of Gandcrab

Since its entry into the cyberspace, Gandcrab ransomware family has affected more or less 500,000 users all around the world. From a technical standpoint, Gandcrab is a cryptovirological Trojan that uses exploit kits, such as RIG and Necurs Botnet to infiltrate into the targeted computers. Before unpacking its payload, the ransomware also checks for security software on the targeted device. Finally, the cryptovirological code is installed on the targeted device through PowerShell script. To lock down the files on the targeted computer, Gandcrab uses RSA encryption module.

GandCrab as RaaS

Different versions of GandCrab ransomware are mostly used as a RaaS, which enables third parties to launch ransomware attacks. The collected extortion amount from successful attacks is then shared between developers of the code and the operators of the attack according to a preset percentage. Unlike many cryptovirological attackers that ask ransomware removal extortion amount in Bitcoins, Gandcrab operators usually demand the ransom in Dash, a relatively less known cryptocurrency.

Simeon Georgiev
https://www.linkedin.com/in/simeon--georgiev/
I am a Cyber Security Enthusiast from Bulgaria. I like to write about malware and ransomware and global cyber attacks. You can reach me on Twitter @sgeorgiev1995 or Email: [email protected]
Previous post Tron ransomware: Another Dharma variant Next post Media Prima Gets hit by a Ransomware Attack

Related Articles

Banking Trojan said to be found in more than 40 low-cost Android models

March 3, 2018Simeon Georgiev
Banking Trojan said to be found in more than 40 low-cost Android models

Is a Third-Party Security really something that I need?

March 3, 2018Simeon Georgiev
Is a Third-Party Security really something that I need?

Combojack Trojan Threatens All Cryptocurrency Addresses Saved on Windows Clipboard

March 6, 2018Simeon Georgiev
Combojack Trojan Threatens All Cryptocurrency Addresses Saved on Windows Clipboard

Latest on Ransomware TV

https://vimeo.com/399908876?loop=0

Recent Posts

  • How to protect your organization against ransomware reinfections
  • AuKill Helps Ransomware Operators Disable EDR and Security Tools
  • AI-ransomware is a real threat, just not a realistic one yet
  • Rorschach is the new speed king in the ransomware space
  • The Role of Supply Chain Breaches in Ransomware Attacks

Stay Protected

Subscribe to our mailing list to get the latest cyber security and ransomware removal articles!

Thank you for subscribing.

Something went wrong.

Navigation

  • Cyber Security
    • Ransomware File Recovery
    • Ransomware Prevention
    • Ransomware Removal
    • Ransomware Types
  • News
  • Tutorials

Ransomware Attacks (Last 6M)

0

Connect & Protect

Facebook
Google+
LinkedIn
YouTube
Vimeo

More

  • BECOME A CONTRIBUTOR

MonsterCloud Reviews

© 2020 MonsterCloud.com. All Rights Reserved.