Cyber SecurityVideo

Who’s Behind the GandCrab Ransomware?

The crooks behind an affiliate program that paid cybercriminals to install the destructive and wildly successful GandCrab ransomware strain announced on May 31, 2019 they were terminating the program after allegedly having earned more than $2 billion in extortion payouts from victims. What follows is a deep dive into who may be responsible for recruiting new members to help spread the contagion.

Image: Malwarebytes.

Like most ransomware strains, the GandCrab ransomware-as-a-service offering held files on infected systems hostage unless and until victims agreed to pay the demanded sum. But GandCrab far eclipsed the success of competing ransomware affiliate programs largely because its authors worked assiduously to update the malware so that it could evade antivirus and other security defenses.

In the 15-month span of the GandCrab affiliate enterprise beginning in January 2018, its curators shipped five major revisions to the code, each corresponding with sneaky new features and bug fixes aimed at thwarting the efforts of computer security firms to stymie the spread of the malware.

“In one year, people who worked with us have earned over US $2 billion,” read the farewell post by the eponymous GandCrab identity on the cybercrime forum Exploit[.]in, where the group recruited many of its distributors. “Our name became a generic term for ransomware in the underground. The average weekly income of the project was equal to US $2.5 million.”

The message continued:

“We ourselves have earned over US $150 million in one year. This money has been successfully cashed out and invested in various legal projects, both online and offline ones. It has been a pleasure to work with you. But, like we said, all things come to an end. We are getting a well-deserved retirement. We are a living proof that you can do evil and get off scot-free. We have proved that one can make a lifetime of money in one year. We have proved that you can become number one by general admission, not in your own conceit.”

Evil indeed, when one considers the damage inflicted on so many individuals and businesses hit by GandCrab — easily the most rapacious and predatory malware of 2018 and well into 2019.

The GandCrab identity on Exploit[.]in periodically posted updates about victim counts and ransom payouts. For example, in late July 2018, GandCrab crowed that a single affiliate of the ransomware rental service had infected 27,031 victims in the previous month alone, receiving about $125,000 in commissions.

The following month, GandCrab bragged that the program in July 2018 netted almost 425,000 victims and extorted more than one million dollars worth of cryptocurrencies, much of which went to affiliates who helped to spread the infections.

Russian security firm Kaspersky Lab estimated that by the time the program ceased operations, GandCrab accounted for up to half of the global ransomware market.

ONEIILK2

It remains unclear how many individuals were active in the core GandCrab malware development team. But KrebsOnSecurity located a number of clues that point to the real-life identity of a Russian man who appears to have been put in charge of recruiting new affiliates for the program.

In November 2018, a GandCrab affiliate posted a screenshot on the Exploit[.]in cybercrime forum of a private message between himself and a forum member known variously as “oneiilk2” and “oneillk2” that showed the latter was in charge of recruiting new members to the ransomware earnings program.

Oneiilk2 also was a successful GandCrab affiliate in his own right. In May 2018, he could be seen in multiple Exploit[.]in threads asking for urgent help obtaining access to hacked businesses in South Korea. These solicitations go on for several weeks that month — with Oneiilk2 saying he’s willing to pay top dollar for the requested resources. At the same time, Oneiilk2 can be seen on Exploit asking for help figuring out how to craft a convincing malware lure using the Korean alphabet.

Later in the month, Oneiilk2 says he no longer needs assistance on that request. Just a few weeks later, security firms began warning that attackers were staging a spam campaign to target South Korean businesses with version 4.3 of GandCrab.

HOTTABYCH

When Oneiilk2 registered on Exploit in January 2015, he used the email address hottabych_k2@mail.ru. That email address and nickname had been used since 2009 to register multiple identities on more than a half dozen cybercrime forums.

In 2010, the hottabych_k2 address was used to register the domain name dedserver[.]ru, a site which marketed dedicated Web servers to individuals involved in various cybercrime projects. That domain registration record included the Russian phone number +7-951-7805896, which mail.ru’s password recovery function says is indeed the phone number used to register the hottabych_k2 email account.

At least four posts made in 2010 to the hosting review service makeserver.ru advertise Dedserver and include images watermarked with the nickname “oneillk2.”

Dedserver also heavily promoted a virtual private networking (VPN) service called vpn-service[.]us to help users obfuscate their true online locations. It’s unclear how closely connected these businesses were, although a cached copy of the Dedserver homepage at Archive.org from 2010 suggests the site’s owners claimed it as their own.

Vpn-service[.]us was registered to the email address sec-service@mail.ru by an individual who used the nickname (and sometimes password) — “Metall2” — across multiple cybercrime forums.

Around the same time the GandCrab affiliate program was kicking into high gear, Oneiilk2 had emerged as one of the most trusted members of Exploit and several other forums. This was evident by measuring the total “reputation points” assigned to him, which are positive or negative feedback awarded by other members with whom the member has previously transacted.

In late 2018, Oneiilk2 was one of the top 20 highest-rated members among thousands of denizens on the Exploit forum, thanks in no small part to his association with the GandCrab enterprise.

Searching on Oneiilk2’s registration email address hottabych_k2@mail.ru via sites that track hacked or leaked databases turned up some curious results. Those records show this individual routinely re-used the same password across multiple accounts: 16061991.

For instance, that email address and password shows up in hacked password databases for an account “oneillk2” at zismo[.]biz, a Russian-language forum dedicated to news about various online money-making affiliate programs.

In a post made on Zismo in 2017, Oneiilk2 states that he lives in a small town with a population of around 400,000, and is engaged in the manufacture of furniture.

HEAVY METALL

Further digging revealed that the hottabych_k2@mail.ru address had also been used to register at least two accounts on the social networking site Vkontakte, the Russian-language equivalent of Facebook.

One of those accounts was registered to a “Igor Kashkov” from Magnitogorsk, Russia, a metal-rich industrial town in southern Russia of around 410,000 residents which is home to the largest iron and steel works in the country.

The Kashkov account used the password “hottabychk2,” the phone number 890808981338, and at one point provided the alternative email address “prokopenko_k2@bk.ru.” However, this appears to have been simply an abandoned account, or at least there are only a couple of sparse updates to the profile.

The more interesting Vkontakte account tied to the hottabych_k2@mail.ru address belongs to a profile under the name “Igor Prokopenko,” who says he also lives in Magnitogorsk. The Igor Prokopenko profile says he has studied and is interested in various types of metallurgy.

There is also a Skype voice-over-IP account tied to an “Igor” from Magnitogorsk whose listed birthday is June 16, 1991. In addition, there is a fairly active Youtube account dating back to 2015 — youtube.com/user/Oneillk2 — that belongs to an Igor Prokopenko from Magnitogorsk.

That Youtube account includes mostly short videos of Mr. Prokopenko angling for fish in a local river and diagnosing problems with his Lada Kalina — a Russian-made automobile line that is quite common across Russia. An account created in January 2018 using the Oneillk2 nickname on a forum for Lada enthusiasts says its owner is 28 years old and lives in Magnitogorsk.

Sources with the ability to check Russian citizenship records identified an Igor Vladimirovich Prokopenko from Magnitogorsk who was born on June 16, 1991.  Recall that “16061991” was the password used by countless online accounts tied to both hottabych_k2@mail.ru and the Oneiilk2/Oneillk2 identities.

To bring all of the above research full circle, Vkontakte’s password reset page shows that the Igor Prokopenko profile is tied to the mobile phone number +7-951-7805896, which is the same number used to set up the email account hottabych_k2@mail.ru almost 10 years ago.

Mr. Prokopenko did not respond to multiple requests for comment.

It is entirely possible that whoever is responsible for operating the GandCrab affiliate program developed an elaborate, years-long disinformation campaign to lead future would-be researchers to an innocent party.

At the same time, it is not uncommon for many Russian malefactors to do little to hide their true identities — at least early on in their careers — perhaps in part because they perceive that there is little likelihood that someone will bother connecting the dots later on, or because maybe they don’t fear arrest and/or prosecution while they reside in Russia. Anyone doubtful about this dynamic would do well to consult the Breadcrumbs series on this blog, which used similar methods as described above to unmask dozens of other major malware purveyors.

It should be noted that the GandCrab affiliate program took measures to prevent the installation of its ransomware on computers residing in Russia or in any of the countries that were previously part of the Soviet Union — referred to as the Commonwealth of Independent States and including Armenia, Belarus, Kazakhstan, Kyrgyzstan, Moldova, Russia, Tajikistan, Turkmenistan, Ukraine and Uzbekistan. This is a typical precaution taken by cybercriminals running malware operations from one of those countries, as they try to avoid making trouble in their own backyards that might attract attention from local law enforcement.

KrebsOnSecurity would like to thank domaintools.com (an advertiser on this site), as well as cyber intelligence firms Intel471, Hold Security and 4IQ for their assistance in researching this post.

Update, July 9, 2:53 p.m. ET: Mr. Prokopenko responded to my requests for comment, although he declined to answer any of the questions I put to him about the above findings. His response was simply, “Hey. You’re wrong. I’m not doing this.” Silly me.


Tags: , , , , , , , , ,

You can skip to the end and leave a comment. Pinging is currently not allowed.

One thought on “Who’s Behind the GandCrab Ransomware?

  • As much as potential, ship out e-mails that are fun loving, with just the very best amount of high energy general tone that may completely create your likelihood time more involved about you. On the precise date, be yourself – the most effective model of you. This can create a number of stress and pressure in the relationship as you might be primarily constructing an individual you have got never truly met. Forcing them to cross the same, for the sake of a budding relationship could invite trouble for each you in addition to your partner. 3. Avoid Trouble – Dating is an exercise that may deliver with it a big baggage of emotions and bodily entailments. With the following pointers, you might be able to plunge into the world of Arab chat sites and take to Arab relationship by storm! Don’t let the on a regular basis up’s and down’s set you again, have a look at let downs as alternatives, people thinking constructive helps to attain constructive outcomes within the relationship world and the rest for that matter.

    Being a successful dater or relationship maker, it’s essential to put time into your own internal happiness, what ever brings that to you retain training it and get good at it, when other singles notice that you are a type of person that is comfortable and content they may feed from that optimistic energy and want to spend high quality time being with you. Get out and socialize, relaxing and hanging out the place the mature singles are spending their time offers you an opportunity to fulfill [url=https://www.love-sites.com/asiame-com-review-4-scam-questions-mostly-asked/]asiame review[/url] other singles and in an atmosphere that makes it easy to strike up conversations. Choose a location and setting where you may have the chance to indicate her who you might be and the prospect to know her better. Many instances singles have discovered success discovering dates by just merely going to the local fitness club and figuring out, this gives you the chance to satisfy different health aware singles and in a relaxed setting like this could make it extra easy and comfortable, therefore serving to you strike up conversations simpler. Online dating websites have grown in reputation and are an effective way to satisfy different like minded local singles. Having the appropriate dating guardrails in place implies that you’ll meet extra appropriate males and discover love true love faster.

    It also makes for some extra enjoyable, informal dates reasonably than it being simply the two of you on a regular basis. Some are joyful being single, but love the company of girls and benefit from the relationship scene. Therefore, if you are looking for an informal fling, Arabic courting sites will not be the perfect choice for you. Therefore, be sure you let the opposite party know of what you are on the lookout for, whether or not it’s friendship, casual flings or a severe relationship that ought to culminate into marriage. Typically, these web sites let you be part of their site free after which give you a free trial period with it. Internet relationship service has proved to be a boon to the lives of many because it has enabled individuals to fulfill and fall in love. If you’re creating your profile for the first time although, online dating could be overwhelming. Make sure you by no means provide your non-public details reminiscent of actual title, telephone numbers, street addresses, and so on in your datingsites consumer profile for absolutely everyone to see. This may result in quite a lot of anxiety and depression in the long term. 4. Define the connection from the beginning – If you’re excited by free Arab relationship portals, remember that on-line relationships may be misconstrued into plenty of things – right from the individuals engaged in the same to the society that they reside in.

    Julie Spira, America’s top online digital courting skilled and founding father of Cyber Dating Expert, has been helping single women and men get dates for 3 a long time. To meet different singles and get dates you have to get yourself outside on the planet and you will be pleasantly stunned how your relationship drought will come to an finish. 2: Join an Online Dating Site for Singles! Does it really feel prefer it has been decades since you have had a date and the pleasure of the primary date that you just met through an online dating site for singles? This can be especially true if you’re utilizing relationship apps to fill your calendar. Then again, teenage dating advice might be troublesome to comply with when, after a discouraging relationship encounter or non-responsive put up on Facebook; you discover your teen comparing themselves to a “boring” financial system car. Get advice from healthy adults. For men and women in Arabic nations such as the Middle-East, in addition to within the Western countries & Asia, online dating and Arab chat sites have turn into one of many prime mediums to use to get to know one another and initiate romantic journeys in life.

    Reply

Leave a Reply

Your email address will not be published. Required fields are marked *