New GandCrab Ransomware Variant Encrypts Files Super Fast

Written byHeloise Montini
Heloise Montini

Heloise Montini is a content writer whose background in journalism make her an asset when researching and writing tech content. Also, her personal aspirations in creative writing and PC gaming make her articles on data storage and data recovery accessible for a wide audience.

Edited byLaura Pompeu
Laura Pompeu

With 10 years of experience in journalism, SEO & digital marketing, Laura Pompeu uses her skills and experience to manage (and sometimes write) content focused on technology and business strategies.

Co-written byBogdan Glushko
Bogdan Glushko

CEO at SalvageData Recovery, Bogdan Glushko has over 18 years of experience in high-security data recovery. Over the years, he's been able to help restore data after logical errors, physical failures, or even ransomware attacks, for individuals, businesses, and government agencies alike.

I think there's an issue with my storage device, but I'm not sure
Start a free evaluation

GandCrab emerged onto the scene back in January. And similar to many ransomware programs, it underwent some changes. Now, there are new wrinkles that promise to challenge even the most vigilant observers.

How Does GandCrab Ransomware Work?

GandCrab is a different cat altogether. Normally, ransomware infects devices via spam email. This is where you’ll receive a message enticing you to click on a link to access “important messages” from your bank, aunt or post office. Once that loads, the malware goes to town, feasting on your files.This isn’t the case with GandCrab. This ransomware uses two different exploit kits. Similar to its name, the ransomware targets vulnerabilities in a system such as Internet Explorer or Flash then uses these weaknesses as distribution points for its malware. This is the RIG exploit kit method.Another method concerns the GrandSoft exploit kit, which works by discovering vulnerabilities in the Java Runtime Environment. From there, the hackers can issue remote attacks with execution codes that encrypt files and demand payment before releasing them back to the user.[caption id="attachment_24032" align="alignnone" width="720"]

Illustration by Pixabay[/caption]

GandCrab’s New Variants

One of the ways hackers continue to perfect their craft is through regular updates of their malware programs and GandCrab is no different in this regard. Fortinet researchers uncovered a change in the ransomware’s code structure.What does this mean? ZDNet reports the ransomware now runs on a Salsa20 steam cipher, meaning it can encrypt data much quicker than previous versions. Another new wrinkle is the method of attack. Now, hackers are targeting WordPress websites. When visiting WordPress, a user might receive a request to download system tools via links, according to a ZDNet report. If the user clicks on the links, it downloads the malware onto their device, rendering their files inaccessible. You’ll know if you’re infected because the ransomware encrypts the files and codes them with the KRAB extension. To prevent this code from holding your files hostage, it’s important to think before acting. Normal WordPress websites won’t ask you to download system tools or anything related to it. It’s similar to visiting ESPN or HGTV’s websites, where you might encounter ads but that should be all.Moreover, it’s an important rule of thumb to avoid clicking on hyperlinks which originate from an unknown source. Similar to refraining from clicking on email attachments from unknown senders, exercise caution when receiving requests to download files via hyperlinks. If you didn’t initiate it (software updates) then it’s best to ignore it.

What Happens if My Files Are Locked?

Losing access to files due to ransomware can be frustrating. However, know there are solutions available. Instead of paying hackers who might or might not return data access, entrust the team at Salvage Data. Our technicians can recover your files from corrupted devices with expedient service that’s affordable and informative. We are proud to offer a free, no-obligation quote from which you’ll receive all the solutions available to you. It’s a risk-free way of discovering how we can help you regain access to your files. Contact us today to take the first step towards recovering your data!

Share this article

Related services

These are the most commonly requested data recovery services. At our headquarters' cleanroom lab, our certified engineers conduct a thorough review of any type of physical storage device, determining if there is logical or physical damage and carefully restoring all of the lost files.ces.

External Drive Data Recovery

We recover data from both external SSD and HDD drives. Rely on certified experts to restore your important files from damaged or corrupted external drives.

/services/data-recovery/external-drive/

Hard Drive Data Recovery

Recover data from all brands of HDD, PC hard drives, and hybrid disks. Our specialists ensure fast and secure recovery for any data loss scenario.

/services/data-recovery/hard-drive/

NAS Data Recovery

Recover data from NAS devices, including RAID configurations. Our team handles all types of NAS systems and ensures data recovery with minimal downtime.

/services/data-recovery/nas/

RAID Data Recovery

Our RAID data recovery services cover RAID 0, 1, 5, 10, and other configurations. We offer expert solutions for failed, degraded, or corrupted RAID arrays.

/services/data-recovery/raid/

SAN Data Recovery

Our team specializes in handling SAN devices from leading manufacturers like Dell EMC, HP, and IBM, ensuring efficient recovery with minimal disruption to your operations.

/services/data-recovery/san/

SD Card Data Recovery

Our recovery experts specialize in restoring data from SD and memory cards. We guarantee quick recovery with a no-data, no-charge policy.

/services/data-recovery/sd-card/

SSD Data Recovery

Our data recovery experts handle all SSD data loss scenarios with advanced tools, ensuring maximum recovery with high-security protocols.

/services/data-recovery/ssd/

USB Flash Drive Data Recovery

Recover lost data from USB flash drives, regardless of the damage or brand. We offer free in-lab evaluations to assess data recovery needs.

/services/data-recovery/usb-flash-drive/

If you’re unsure about which data recovery service to choose, let our team assist you in selecting the appropriate solutions. We understand the anxiety that comes with a sudden drive failure, and we are more prompt in our actions compared to other recovery service providers.