TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Krebs on Security

Germany Doxes “UNKN,” Head of RU Ransomware Gangs REvil, GandCrab

BrianKrebs · 2026-04-06 · Read original ↗

ATT&CK techniques detected

8 predictions
T1486Data Encrypted for Impact
95%
"purview, focusing instead on improving the quality of their ransomware. the higher quality ransomware — which, in many cases, the hunting team could not break — resulted in more and higher pay - outs from victims. the monumental payments enabled gangs to reinvest in their enterpr…"
T1486Data Encrypted for Impact
93%
"in the forum ’ s escrow to show he meant business. by this time, many cybersecurity experts had concluded revil was little more than a reorganization of gandcrab. unknown also gave an interview to dmitry smilyanets, a former malicious hacker hired by recorded future, wherein unkn…"
T1486Data Encrypted for Impact
84%
"k. a. unkn, and anatoly sergeevitsch karvchuk, alleged leaders of the gandcrab and revil ransomware groups. germany ’ s bka said shchukin acted as the head of one of the largest worldwide operating ransomware groups gandcrab and revil, which pioneered the practice of double extor…"
T1486Data Encrypted for Impact
68%
"germany doxes “ unkn, ” head of ru ransomware gangs revil, gandcrab an elusive hacker who went by the handle “ unkn ” and ran the early russian ransomware groups gandcrab and revil now has a name and a face. authorities in germany say 31 - year - old russian daniil maksimovich sh…"
T1657Financial Theft
60%
"of extracting hefty extortion payments from victims, largely going after organizations with more than $ 100 million in annual revenues and fat new cyber insurance policies that were known to pay out. over the july 4, 2021 weekend in the united states, revil hacked into and extort…"
T1657Financial Theft
58%
"##dcrab team would then try to expand that access, often siphoning vast amounts of sensitive and internal documents in the process. the malware ’ s curators shipped five major revisions to the gandcrab code, each corresponding with sneaky new features and bug fixes aimed at thwar…"
T1486Data Encrypted for Impact
45%
"of extracting hefty extortion payments from victims, largely going after organizations with more than $ 100 million in annual revenues and fat new cyber insurance policies that were known to pay out. over the july 4, 2021 weekend in the united states, revil hacked into and extort…"
T1657Financial Theft
39%
"k. a. unkn, and anatoly sergeevitsch karvchuk, alleged leaders of the gandcrab and revil ransomware groups. germany ’ s bka said shchukin acted as the head of one of the largest worldwide operating ransomware groups gandcrab and revil, which pioneered the practice of double extor…"

Summary

An elusive hacker who went by the handle "UNKN" and ran the early Russian ransomware groups GandCrab and REvil now has a name and a face. Authorities in Germany say 31-year-old Russian Daniil Maksimovich Shchukin headed both cybercrime gangs and helped carry out at least 130 acts of computer sabotage and extortion against victims across the country between 2019 and 2021.