Skip to content

Davey Winder

delivering award-winning technology journalism since 1991

  • home
  • about me
  • follow me on mastodon
  • privacy policy
  • Toggle search form
photo of a crab

GandCrab blends old and new threat resources as ransomware evolves

Posted on February 2, 2018February 2, 2018 By Davey Winder

GandCrab features distribution methodology and ransom currency choices that might be pointers as to how ransomware will evolve in 2018

GandCrab is distributed using two exploit kits, namely RIG EK and GrandSoft EK. Researchers at Malwarebytes Labs call this out as surprising, as other than the Magnitude EK kit which is known to push one particular ransomware attack (Magniber) the typical kit payload has been anything but ransomware of late. Then there’s the fact that GandCrab has opted not to ask for a ransom paid in Bitcoin, instead looking for payment using the Dash cryptocurrency.
So, just how unusual is it for an exploit kit, let alone two, to be distributing ransomware in 2018? Paolo Passeri, a solutions architect at Netskope, reckons the last examples of exploit kits pushing ransomware date back to the end of last year with Matrix and Princess. “It’s interesting to notice that RIG is involved for both of these” he says “whereas GrandSoft is a blast from the past, first appearing in 2012 and it was thought that it had disappeared.” Liviu Arsene, senior e-threat analyst at Bitdefender, told SC Media UK that while some exploit kits such as Terror or Magnitude are still being occasionally used to deliver ransomware, these campaigns are usually highly targeted at specific regions. “Booby-trapped email attachments and macros within documents have become the new norm in disseminating ransomware” Arsene concludes “as they can affect a significantly larger pool of victims.”
Click here to read complete article
Analysis Tags:Cryptocurrency, exploit kits, ransomware

Post navigation

Previous Post: It’s all gravy for the onion router as Tor Browser beefs up security
Next Post: The NHS phishing threat and how to fight it

Related Articles

Forget Passwords, This New Tech Is Nearly Hacker-Proof, 1Password Says Analysis
Gmail Hackers Leave Vital Clues Behind—Check These 3 Things Now Analysis
No, 1Password Has Not Just Been Hacked—Your Passwords Are Safe Analysis
New Critical Security Warning For iPhone, iPad, Watch, Mac—Attacks Underway Analysis
New Emergency Chrome Security Update After Critical iOS 16.6.1 Release Analysis
New iPhone iOS 16 Bluetooth Hack Attack—How To Stop It Analysis

Categories

Post Archive

Tags

0day Analysis Android Apple Apps breach bug bounty Business Chrome crime Cybercrime Data Protection Encryption Enterprise Google Government Hackers Hacking Health healthcare industry iOS IoT iPhone Malware Microsoft News NHS Opinion passwords Phishing Privacy ransomware Research Russia Samsung threat intelligence Twitter Update Vulnerabilites vulnerabilities Vulnerability Windows Windows 10 zero-day

Copyright © 2025 Davey Winder .

×
Cookies
We serve cookies. If you think that's ok, just click "Accept all". You can also choose what kind of cookies you want by clicking "Settings". Read our cookie policy
Settings Refuse all Accept all
Cookies
Choose what kind of cookies to accept. Your choice will be saved for one year. Read our cookie policy
  • Necessary
    These cookies are not optional. They are needed for the website to function.
  • Statistics
    In order for us to improve the website's functionality and structure, based on how the website is used.
  • Experience
    In order for our website to perform as well as possible during your visit. If you refuse these cookies, some functionality will disappear from the website.
  • Marketing
    By sharing your interests and behavior as you visit our site, you increase the chance of seeing personalized content and offers.
Save Refuse all Accept all
GDPR Cookie Policy