# German Authorities Identify GandCrab and REvil Ransomware Leaders

> German and US authorities identify Russian nationals behind GandCrab and REvil ransomware operations, marking a major step in ransomware attribution.

- Published: 2026-04-07T00:40:37.000Z
- Severity: high
- Category: Threat Intel
- Tags: REvil, GandCrab, Ransomware, Attribution, BKA, Law Enforcement
- Author: Runtime Rebel Intel
- Primary source: https://www.bleepingcomputer.com/news/security/german-authorities-identify-revil-and-gangcrab-ransomware-bosses/
- Canonical: https://runtimerebel.com/blog/german-authorities-identify-gandcrab-and-revil-ransomware-leaders

## Key points

- German authorities and the US DOJ identified key leaders of the GandCrab and REvil ransomware operations active between 2018 and 2021.
- These operations targeted thousands of victims worldwide, including critical infrastructure, using a ransomware-as-a-service business model.
- Organizations must maintain offline backups and implement multi-factor authentication to prevent similar ransomware attacks from current threat actors.

## Overview of the REvil and GandCrab Attribution

According to [BleepingComputer](https://www.bleepingcomputer.com/news/security/german-authorities-identify-revil-and-gangcrab-ransomware-bosses/), the German Federal Criminal Police (BKA) and the US Department of Justice (DOJ) have successfully identified Russian nationals allegedly responsible for leading the GandCrab and [REvil](https://en.wikipedia.org/wiki/REvil) [Ransomware](/glossary#ransomware) operations. One of the primary suspects, Nikolay Nikolayevich Chernov (known by the alias "ReshaEVIL"), is accused of acting as a core administrator and developer for both groups. This identification is the result of years of international law enforcement cooperation, tracking the movement of digital assets and communication logs from the peak of these groups' activities between 2019 and 2021.

### Impact of Identifying REvil Ransomware Leaders

The identification of these individuals provides significant insight into the Ransomware-as-a-Service (RaaS) model. GandCrab, which debuted in early 2018, was one of the most prolific ransomware operations of its time until it claimed to retire in May 2019. Shortly thereafter, REvil (also known as Sodinokibi) emerged, utilizing similar codebases and [TTP](/glossary#ttp). Security researchers have long suspected a direct link between the two, and these recent attribution findings confirm the personnel overlap at the leadership level.

For defenders, the primary value in identifying REvil ransomware leaders lies in the historical analysis of their infrastructure and methodology. By understanding who directed these operations, [SOC](/glossary#soc) teams can better correlate historical [IoC](/glossary#ioc) and [C2](/glossary#c2) patterns to modern spin-off groups. Many former affiliates of these gangs have migrated to other operations, such as LockBit or BlackCat, bringing their preferred methods of [Lateral Movement](/glossary#lateral-movement) and data exfiltration with them.

## Technical Analysis of Operational Evolution

GandCrab and REvil specialized in high-volume, high-impact attacks. They often gained initial access via [Phishing](/glossary#phishing) or by exploiting vulnerabilities in internet-facing services. Once inside a network, they would attempt [Privilege Escalation](/glossary#privilege-escalation) to gain domain administrator rights before deploying the encryptor.

### Historical GandCrab Ransomware Attribution Findings

Investigation into the "ReshaEVIL" alias revealed a connection to the development of the GandCrab affiliate panel. This panel allowed low-level attackers to manage their own campaigns, track victims, and negotiate ransoms, while the core developers took a percentage of the profits. This decentralized model made the groups resilient to targeted law enforcement actions against individual affiliates for several years.

The transition from GandCrab to REvil marked an evolution in extortion tactics. While GandCrab focused largely on volume, REvil pioneered the "double extortion" method. This involves not only encrypting the victim's data but also stealing sensitive information and threatening to leak it on a dedicated "shame site" if the ransom is not paid. This TTP has since become the standard for most modern ransomware groups.

## Mitigation and Defensive Recommendations

While GandCrab and REvil are no longer active in their original forms, their successors continue to use similar techniques. Implementing [REvil ransomware mitigation steps](/glossary#ransomware) remains vital for modern enterprise security to defend against the RaaS ecosystem.

*   **Multi-Factor Authentication (MFA):** Ensure all remote access points, including VPNs and RDP, require MFA to prevent unauthorized access via stolen credentials.
*   **Offline Backups:** Maintain immutable, off-site backups of critical data to ensure recovery without paying a ransom in the event of an encryption event.
*   **Network Segmentation:** Limit the ability of attackers to perform lateral movement by segmenting sensitive assets from general user environments and monitoring inter-zone traffic.
*   **Vulnerability Management:** Regularly patch internet-facing software to prevent [RCE](/glossary#rce) exploits that often serve as the initial entry point for ransomware groups.

Security professionals should use the [MITRE ATT&CK](/glossary#mitre-att-ck) framework to map out common ransomware behaviors. By focusing on the detection of credential dumping and unauthorized data staging, organizations can interrupt the kill chain before encryption occurs.

**Related:** [Germany Doxes UNKN: Identity of REvil and GandCrab Leader Revealed](/blog/germany-doxes-unkn-identity-of-revil-and-gandcrab-leader-revealed), [BKA Unmasks REvil Leadership Behind 130 German Ransomware Attacks](/blog/bka-unmasks-revil-leadership-behind-130-german-ransomware-attacks)

---

AI-generated analysis from the primary source above; not human-reviewed before publication — verify anything operational against the original (https://runtimerebel.com/editorial). Quote with attribution and a link to the canonical URL: https://runtimerebel.com/blog/german-authorities-identify-gandcrab-and-revil-ransomware-leaders
