How GandCrab Ransomware Made Its Developers Nine Figures

How GandCrab Ransomware Made Its Developers Nine Figures Featured Image

2018 was the year where malware stopped being a malicious hobby and became a real money-making venture. The rise in ransomware and cryptomining attacks is a clear sign that hackers no longer want to just cause havoc – they also want to make a pretty penny while they do so.

Up until now we’ve had no real income figures to work with; were hackers living the dream, or getting by on scraps? It was clear that hackers were trying to make money, but there was no sign on whether they were succeeding. Recently BitDefender released an estimate on the most popular ransomware of this year, and the figures were a little worrisome .

How Much Is Being Made?

gandcrab-money

We saw some fledgling ransomware attacks around the start of 2018. Things began to kick off when hackers began adopting GandCrab as their weapon of choice back in February 2018. GandCrab was offered as ransomware-as-a-service, where a developer allows others to use their malicious software for either an upfront cost or a share of the total cut. This meant that the developers of GandCrab got a slice of the pie every time someone used their software to successfully carry out an attack.

With GandCrab available for cybercriminals to launch their attacks, how much did its developers make? While BitDefender didn’t have access to the income logs of the developers, they were able to use some educated logic to make a guess-timate.

We know that 500,000 users were infected with GandCrab. We also know that the absolute minimum ransom bounty was $600. Around half of the total people infected with GandCrab give up and pay out. That already gives you a $150 million figure at the absolute least. BitDefender believes the actual figure comes to around $300 million, given how some of the higher ransom demands reached an eye-watering $700,000.

This is an absolutely stunning figure, as this was a movement that started early in 2018. With these numbers being thrown around, it’s not hard to see why ransomware is quickly become the biggest threat of 2018.

How Did this Happen?

With such rapid development in just under nine months, it begs the question: how did GandCrab manage to rake in the big bucks so quickly? While malware such as WannaCry did the rounds earlier this year, it didn’t quite have the same impact as GandCrab. This is because GandCrab does something that WannaCry could only dream of doing – target individual users.

gandcrab-ransomware

GandCrab comes with the ability to customise the ransom message and payment amount from each victim. Gone are the days where ransomware developers carpet-bomb as many users as possible in the hopes they hit someone who’s both rich and has a strong desire to save their files. Now they can individually tweak the malware to suit their targets. They can customise the malware to suit the target’s ability to pay and ensure they’re getting the most possible out of their victims.

This method of extraction was demoed by IBM with their DeepLocker malware, which used webcams to scan the faces of users and lock down the PC of the target it was looking for. Infecting the PCs of people who can’t pay or aren’t worried about losing their files only makes the malware more visible and susceptible to a counterattack. Using the initial window of freedom to hit affluent targets ensures a nice payout until the ransomware is solved and a solution is released.

What’s Being Done?

gandcrab-shield

Thankfully, security experts around the world realise how bad a ransomware epidemic can be. Reverse-engineering a ransomware attack can make it effectively powerless, and people are pushing out decrypters to fight the latest versions of GandCrab. Of course, being diligent with your Internet security also goes a good distance for avoiding being infected!

Money Grab Crab

We’ve known for a while that malware is shifting towards making profit. Despite this, we didn’t know how much hackers were actually making. With nine-digit estimates being suggested, malware is now a highly profitable venture for those who can muster it.

Do you think this is the start of a wave of malware trying to emulate GandCrab’s success? Or are we ready for the onslaught? Let us know below.

Subscribe to our newsletter!

Our latest tutorials delivered straight to your inbox

Simon Batt Avatar

Read next

When Sony shipped the first Walkman in 1979, chairman Akio Morita insisted on a second headphone jack and a “hotline” talk button, convinced it would be rude for one person to listen to music alone — and within a few years buyers had ignored the sociable features so completely that Sony quietly dropped them
Russia still custom-builds the Soyuz return seats for ISS crew members using plaster casts taken weeks before launch, because astronauts grow as much as five centimetres taller during a long-duration stay and a seat moulded to their Earth-shaped spine would no longer fit the body that comes home
The “CrackBerry” nickname stuck for a reason — and the variable-reward psychology that hooked early-2000s executives on their BlackBerrys is the exact same machinery now running every push notification on every smartphone in your pocket
In 1843, Ada Lovelace described a brass-and-punched-card engine that could act on symbols as well as numbers, even composing music if harmony could be reduced to rules, inside seven translator’s notes three times longer than the paper itself
ARPANET sent its first message on 29 October 1969 from a lab at UCLA to a machine at Stanford, and the message was supposed to read ‘LOGIN’ — but the system crashed after the L and the O, meaning the first word ever transmitted over the network that became the internet was, by accident, ‘LO’.
In 1995, Microsoft shipped a cartoon-house interface called Bob, led by Melinda French, who married Bill Gates while it was in development — it demanded twice the memory of a typical home PC, sold roughly 30,000 copies, and was dead within a year, leaving behind the font Comic Sans and the animated assistant that became Clippy.
The Greenland shark grows about one centimetre a year, does not reach sexual maturity until around age 150, and a specimen carbon-dated by Danish researchers in 2016 was estimated to be at least 272 years old, meaning it was already swimming the North Atlantic when Mozart was composing symphonies.
When Apple shipped iOS 12 in June 2018, a small feature called Screen Time slipped onto every iPhone with a counter nobody had quite prepared for — a tally of pickups — and within a day Tim Cook was telling CNN the number of times he picked up his own phone was simply too many