PLATFORM:

Windows

 OVERALL RISK RATING:
 REPORTED INFECTION:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  OVERVIEW

Gandcrab ransomware, discovered near the end of January 2018, operates on a ransomware-as-a-service (RaaS) model. It is the first ransomware that demands payment in DASH cryptocurrency, which is more complicated to trace and uses the .bit top level domain (TLD).

Some Gandcrab campaigns use malvertising and exploits vulnerabilities related to Apache Struts, JBoss, Weblogic and Apache Tomcat.

It is capable of the following:

  • File encryption

  • Disabling system

  • Propagation

  • Downloading files

Gandcrab ransomware typically follows the infection chain below: