Gbhackers German Authorities Identify Leaders of REvil and GandCrab Ransomware Gangs
Article Content
- •Daniil Shchukin and Anatoly Kravchuk identified as leaders of REvil and GandCrab gangs.
- •The gangs executed at least 130 cyberattacks in Germany, causing over €35 million in damages.
- •Shchukin is known for pioneering the double extortion tactic in ransomware operations.
German Federal Criminal Police (BKA) have identified Daniil Maksimovich Shchukin, 31, and Anatoly Sergeevitsch Kravchuk, 43, as the leaders of the notorious REvil and GandCrab ransomware gangs. Shchukin, known by the alias 'UNKN,' is linked to at least 130 cyberattacks in Germany from 2019 to 2021, resulting in approximately €2 million in ransom payments and over €35 million in economic damage. Both gangs were known for pioneering the double extortion tactic, demanding payments for decryption keys and to prevent data leaks. The BKA has issued a public appeal for information regarding their whereabouts, as both suspects are believed to be in Russia. This identification marks a significant milestone in the ongoing efforts to combat ransomware operations that have plagued organizations globally. The REvil gang, in particular, gained notoriety for targeting large enterprises and conducting high-profile attacks, including the Kaseya incident that affected around 1,500 downstream victims.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (19)
Following this threat?
Track GandCrab, Sodinokibi and Acer in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
SonicWall Report Highlights Cyber Threats to Professional Services Firms SonicWall's 2026 Professional Services Protect Brief reveals that professional services firms, including law firms and managed service providers, experienced 3 billion IPS events in the first half of 2026, marking the highest attack volume across tracked industries. The report indicates that 460 organizations in this…
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…