Gandcrab malware family
Gandcrab is a malware family tracked by MalwareAnalyzer by Cyble across 3 publicly analyzed samples. First seen 2026-07-30, most recently 2026-08-22. Observed ATT&CK techniques include T1112, T1071.001, T1543.003.
Corpus statistics
- Publicly analyzed samples: 3
- First seen: 2026-07-30
- Last seen: 2026-08-22
- Verdicts: malicious 3
- File types: pe 3
ATT&CK techniques used by Gandcrab
Recent Gandcrab samples
- 05ff912ac3a5ee829e69388ec7cc7e39794ee60ecb797c620d4d5475fb5be2c7 - malicious (2026-08-22)
- 31bbc9f6a7d5b5c248c6379afcf7c7026fb0f3b521016d918edba1fad085a9cc - malicious (2026-08-08)
- b06ab1f3abf8262f32c3deab9d344d241e4203235043fe996cb499ed2fdf17c4 - malicious (2026-07-30)
Frequently asked about Gandcrab
- What is Gandcrab?
- Gandcrab is a malware family tracked by MalwareAnalyzer by Cyble across 3 publicly analyzed samples. First seen 2026-07-30, most recently 2026-08-22. Observed ATT&CK techniques include T1112, T1071.001, T1543.003.
- How many Gandcrab samples have been analyzed?
- MalwareAnalyzer by Cyble holds 3 publicly analyzed samples attributed to Gandcrab, first seen 2026-07-30 and most recently 2026-08-22. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What MITRE ATT&CK techniques does Gandcrab use?
- Across our Gandcrab samples the most frequently observed techniques are T1112 (2), T1071.001 (1), T1543.003 (1). Counts are the number of analyzed samples in which each technique was observed.
- What file types does Gandcrab use?
- Gandcrab samples in this corpus are distributed as pe (3).
- Is Gandcrab malicious?
- 3 of 3 analyzed Gandcrab samples were scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends