Users Beware: Dash Ransomware “GandCrab” of Russian Origin Infecting PDF Files by stoneheart

View this thread on steempeak.com
· @stoneheart ·
$0.02
Users Beware: Dash Ransomware “GandCrab” of Russian Origin Infecting PDF Files
![image](https://img.esteem.ws/fs25zi8s4x.jpg)

There’s a new ransomware on the loose, targeting unsuspecting victims’ computers by way of malicious downloadable PDF files. Before delving any deeper, BTCManager reminds all readers to exercise the utmost precaution while downloading PDF files from unknown senders.

What is GandCrab?
The looming threat came into the limelight after LMNTRIX, an Australian cybersecurity firm, published a report earlier in February 2018 claiming that a newly engineered ransomware dubbed “GandCrab” is being promoted on the dark web as a ransomware-as-a-service to cyber thugs. The content of the promotional campaign is in Russian, the security firm added.

If the term ransomware doesn’t ring a bell, it’s high time to investigate the security threat. While it is relatively new, it is also positioned as one of the worst forms of malware you are at risk of encountering.

Upon breaching the victim’s computer, a ransomware virus encrypts a user’s content, making it inaccessible. The only way the victim can hope to regain access to their content is by paying a hefty ransom to the perpetrators.

According to the LMNTRIX report, the GandCrab is developed in such a way that anybody can buy it online through a shady dark web marketplace. Once they purchase it, the buyer becomes a member of the extended GandCrab network. Any money made by victimizing unsuspecting users is then split between the developers and the members by a ratio of 60:40.

The members, however, have the option of increasing their shares up to 70 percent if they are able to breach a large number of computers successfully.

There are a few conditions to fulfill before the agents can get started, however. To use the ransomware to make money, members must register with the network and apply. Additionally, members are also prohibited from targeting users from the former Soviet Republic nations including the Commonwealth of Independent States (CIS).

How does GandCrab work?
The LMNTRIX report states that GandCrab makes use of RIG and GrandSoft exploit kits to spread and target computers. This technique is somewhat unique considering that said exploit kits are traditionally associated with malware such as trojans, and crypto miners.

There are no known reports of other ransomware in the past that depend on exploit kits to transmit and infect. Even more surprisingly, the exploit kit GandCrab uses was thought to have disappeared for some time.

Among other key findings, the LMNTRIX report also claims that the ransomware’s servers use a .bit domain. This information is significant given that the .bit domain is not included in the traditional ICANN authorized DNS and requires all payments to be handled using cryptocurrencies only.

Of the cryptocurrencies allegedly leveraged, Dash seems to be the preferred token of choice in this case as it offers a higher degree of anonymity compared to most other coins.

Each Dash token is equivalent to around $740, and the GandCrab ransomware demands 1.5 Dash from its victims, which translates to roughly $1,100 at press time. If the victim fails to pay the ransom within the stipulated period, the ransom price doubles.
👍  , , , , ,
properties (23)
post_id33,397,061
authorstoneheart
permlinkusers-beware-dash-ransomware-gandcrab-of-russian-origin-infecting-pdf-files-8564c62c78d96
categorybitcoin
json_metadata"{"format": "markdown+html", "community": "esteem", "links": [], "app": "esteem/1.5.1", "tags": ["bitcoin", "crypto", "story", "news", "blockchain"], "image": ["https://img.esteem.ws/fs25zi8s4x.jpg"]}"
created2018-02-18 00:50:30
last_update2018-02-18 00:50:30
depth0
children2
net_rshares4,484,778,941
last_payout2018-02-25 00:50:30
cashout_time1969-12-31 23:59:59
total_payout_value0.023 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length3,186
author_reputation119,919,245,915
root_title"Users Beware: Dash Ransomware “GandCrab” of Russian Origin Infecting PDF Files"
beneficiaries
0.
accountesteemapp
weight1,000
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
author_curate_reward""
vote details (6)
@cheetah ·
Hi! I am a robot. I just upvoted you! I found similar content that readers might be interested in:
https://thebitcoinnews.com/users-beware-dash-ransomware-gandcrab-of-russian-origin-infecting-pdf-files/
properties (22)
post_id33,397,098
authorcheetah
permlinkcheetah-re-stoneheartusers-beware-dash-ransomware-gandcrab-of-russian-origin-infecting-pdf-files-8564c62c78d96
categorybitcoin
json_metadata{}
created2018-02-18 00:50:45
last_update2018-02-18 00:50:45
depth1
children1
net_rshares0
last_payout2018-02-25 00:50:45
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length202
author_reputation750,854,098,279,735
root_title"Users Beware: Dash Ransomware “GandCrab” of Russian Origin Infecting PDF Files"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000
@umerfarooqorak ·
I like your work dear
You and analyst @salahuddin2004 are two top analysts of cryptoworld.
properties (22)
post_id33,397,268
authorumerfarooqorak
permlinkre-cheetah-cheetah-re-stoneheartusers-beware-dash-ransomware-gandcrab-of-russian-origin-infecting-pdf-files-8564c62c78d96-20180218t005151766z
categorybitcoin
json_metadata"{"app": "steemit/0.1", "users": ["salahuddin2004"], "tags": ["bitcoin"]}"
created2018-02-18 00:51:54
last_update2018-02-18 00:51:54
depth2
children0
net_rshares0
last_payout2018-02-25 00:51:54
cashout_time1969-12-31 23:59:59
total_payout_value0.000 SBD
curator_payout_value0.000 SBD
pending_payout_value0.000 SBD
promoted0.000 SBD
body_length90
author_reputation-7,244,359,600
root_title"Users Beware: Dash Ransomware “GandCrab” of Russian Origin Infecting PDF Files"
beneficiaries[]
max_accepted_payout1,000,000.000 SBD
percent_steem_dollars10,000