October 19, 2018 By Douglas Bonderud 2 min read

GandCrab ransomware has evolved again, and the newest version features a partnership with NTCrypt to facilitate code obfuscation and frustrate security researchers.

As noted by McAfee, GandCrab’s authors deployed version 5 of the ransomware on Sept. 27. Since first appearing in January 2018, the code’s authors have released regular updates that both improved functionality and introduced new bugs.

As the McAfee report put it, the ransomware authors “are undoubtedly confident and have strong marketing skills, but flawless programming is not one of their strengths.” Still, public endorsement of FalloutEK and a new partnership with NTCrypt suggest that GandCrab is looking to claw its way into as many devices as possible with this new iteration.

What Does GandCrab’s Development Mean for Malware Security?

The makers of GandCrab aren’t afraid of notoriety; each new release comes with flashy announcements and promises of new partnerships. As a result, a members-only club of affiliates has developed around GandCrab, with more waiting in the wings to distribute the ransomware. GandCrab’s popularity has also led to partnerships with other criminal groups, which has helped the malware evolve from a simple infection vector to a more sophisticated ransomware-as-a-service.

Particularly concerning is GandCrab’s ability to attract other criminal groups. Its partnership with NTCrypt was established by way of competition: The crypter received $500 from the developers and free advertising in all of GandCrab advertisements. Beyond the obfuscation offered by NTCrypt services, this recruiting method provides a way for malware developers to avoid low-quality partners while diversifying their supply chain.

The ransomware uses multiple attack vectors to infect devices, encrypt files and demand cryptocurrency, including remote desktop connections, phishing emails, legitimate programs with hidden Trojans, exploit kits, PowerShell scripts and botnets such as Phorpiex.

How to Avoid the Pinch of GandCrab’s Code Obfuscation

Although the GandCrab developers are working hard to deliver regular updates, their lack of coding sophistication also introduces bugs that limit functionality or cause outright failure. For example, a compiling flaw in version 5 relies on a dynamic-link library (DLL) not available in Windows Vista or XP, meaning the malware will only work on machines running Windows 7 or later. The authors also claimed that their code doesn’t rely on existing CVE’s, but this is inaccurate — GandCrab uses both CVE-2018-8440 and CVE-2018-8120.

Despite its flaws, however, GandCrab remains a potent attack vector. To counter this type of malware security threat, security experts recommend establishing a security baseline, incorporating security best practices into all endpoint builds and ensuring a consistent “golden image” that adheres to your security policy. Security teams should also create and maintain a live inventory of all devices to help pinpoint malware infections, and develop “an aggressive and current patch management policy” to help mitigate the impact of existing vulnerabilities.

Source: McAfee

More from

NIST’s role in the global tech race against AI

4 min read - Last year, the United States Secretary of Commerce announced that the National Institute of Standards and Technology (NIST) has been put in charge of launching a new public working group on artificial intelligence (AI) that will build on the success of the NIST AI Risk Management Framework to address this rapidly advancing technology.However, recent budget cuts at NIST, along with a lack of strategy implementation, have called into question the agency’s ability to lead this critical effort. Ultimately, the success…

Researchers develop malicious AI ‘worm’ targeting generative AI systems

2 min read - Researchers have created a new, never-seen-before kind of malware they call the "Morris II" worm, which uses popular AI services to spread itself, infect new systems and steal data. The name references the original Morris computer worm that wreaked havoc on the internet in 1988.The worm demonstrates the potential dangers of AI security threats and creates a new urgency around securing AI models.New worm utilizes adversarial self-replicating promptThe researchers from Cornell Tech, the Israel Institute of Technology and Intuit, used what’s…

Passwords, passkeys and familiarity bias

5 min read - As passkey (passwordless authentication) adoption proceeds, misconceptions abound. There appears to be a widespread impression that passkeys may be more convenient and less secure than passwords. The reality is that they are both more secure and more convenient — possibly a first in cybersecurity.Most of us could be forgiven for not realizing passwordless authentication is more secure than passwords. Thinking back to the first couple of use cases I was exposed to — a phone operating system (OS) and a…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today