• Cyber Security
    • Ransomware Prevention
    • Ransomware Removal
    • Ransomware File Recovery
    • Ransomware Types
  • Ransomware Services
    • Ransomware Removal
    • Ransomware File Recovery
  • News
  • Tutorials
  • Ransomware TV

GandCrab Version 5.0 – A Cryptovirological Discovery

October 4, 2018Simeon Georgiev

The operators of infamous GandCrab ransomware have exceptional ‘work ethics’ because they never cease to work and improve their cryptovirological strain. Malware hunters have recently discovered a new variant of the ransomware. After the latest discovery, there are now five versions lingering in the cyber world. It is important to note that this ransomware family was first made its entry into the cyberspace in January 2018

According to initial inspection of the latest GandCrab version, experts have found out that it is using slightly different encryption module to lock down the files on affected devices. Instead of using the combination of AES and RSA encryption modules like earlier versions, GandCrab V 5.0 is using the mix of Salsa20 and RSA encryption mechanisms.

Due to a different encryption method, experts are still trying to work out an effective ransomware removal measure. According to the ransom note that appears in an HTML file format, the GandCrab operators are asking for $2,400 in Dash or Bitcoin for ransomware removal. The new GandCrab variant also connects to the command and control server as soon as the cryptovirological payload is delivered and unpacked on the affected device. Command and control servers actually notify attackers with the real-time activity of ransomware on the affected device.

One peculiar thing regarding the activity of GandCrab V5.0 is that it uses a string of five random characters as an extension for every locked down the file. Ransomware experts are advising the affected to users to be patient and wait for professional ransomware removal solution instead of paying the attackers.

Experts have yet to find what distribution mechanism is used by the operators. They are sure that GandCrab operators are not using exploit kits for distributing the latest version. So, there are strong chances that brute-force or email spamming is being used for distributing the strain.

Simeon Georgiev
https://www.linkedin.com/in/simeon--georgiev/
I am a Cyber Security Enthusiast from Bulgaria. I like to write about malware and ransomware and global cyber attacks. You can reach me on Twitter @sgeorgiev1995 or Email: [email protected]
Previous post Hacked Surveillance Cameras in Washington DC – A Two Year Chase for the Ransomware Attack Perpetrators Next post Honolulu-Based Medical Facility Attacked

Related Articles

NonPetya Ransomware Caused Millions of Dollars Worth of Damage to Maersk

January 27, 2018Simeon Georgiev
NonPetya Ransomware Caused Millions of Dollars Worth of Damage to Maersk

Ransomware: 4 Types of the Latest Trend in Cybercrimes

February 1, 2018Simeon Georgiev
Ransomware: 4 Types of the Latest Trend in Cybercrimes

NonPetya Ransomware Caused Millions of Dollars Worth of Damage to Maersk

February 1, 2018Simeon Georgiev
NonPetya Ransomware Caused Millions of Dollars Worth of Damage to Maersk

Latest on Ransomware TV

https://vimeo.com/399908876?loop=0

Recent Posts

  • How to protect your organization against ransomware reinfections
  • AuKill Helps Ransomware Operators Disable EDR and Security Tools
  • AI-ransomware is a real threat, just not a realistic one yet
  • Rorschach is the new speed king in the ransomware space
  • The Role of Supply Chain Breaches in Ransomware Attacks

Stay Protected

Subscribe to our mailing list to get the latest cyber security and ransomware removal articles!

Thank you for subscribing.

Something went wrong.

Navigation

  • Cyber Security
    • Ransomware File Recovery
    • Ransomware Prevention
    • Ransomware Removal
    • Ransomware Types
  • News
  • Tutorials

Ransomware Attacks (Last 6M)

0

Connect & Protect

Facebook
Google+
LinkedIn
YouTube
Vimeo

More

  • BECOME A CONTRIBUTOR

MonsterCloud Reviews

© 2020 MonsterCloud.com. All Rights Reserved.