The identification of Daniil Maksimovich Shchukin (UNKN), leader of the GandCrab and REvil ransomware gangs that extorted $2B+, is analyzed alongside their hallmark double-extortion tactics (encryption plus data-leak threats).
Organizations targeted by GandCrab/REvil-style ransomware operations.
Double extortion maximizes payment pressure by combining encryption with threatened data exposure.
- Maintain offline backups and rehearse recovery.
- Hunt for encoded scripting and anomalous C2.
- Deploy behavioral endpoint protection and segmentation.
- Train staff against phishing initial access.
Key Technical Findings
Ransomware-operator and TTP analysis (UNKN / GandCrab / REvil).
Enterprises targeted by these operations.
Exploits or phishing.
Ransomware payload deployment.
Mechanisms for continuous access.
Gaining higher permissions.
Techniques to avoid detection.
Harvested for lateral movement.
Movement to high-value targets.
Exfiltration before encryption (double extortion); C2 over application-layer protocols (T1071).
High – encryption (T1486) plus leak threats.
Technical Background
UNKN led GandCrab and REvil, which combined technical exploitation with psychological pressure via double extortion – encrypting data (T1486) and threatening to publish exfiltrated information. The full chain spans access, execution, persistence, escalation, evasion, credential access, discovery, lateral movement, collection, C2 over application-layer protocols (T1071), exfiltration, and impact.
Defenses center on offline backups, behavioral endpoint protection, segmentation, encoded-scripting and C2 detection, and phishing-aware training.
Attack Chain Analysis
-
Initial Access
ActivityExploit or phish.
EvidenceExploit/phishing precursors.
TelemetryEDR, email/web logs.
Detection opportunityCorrelate access with payload activity.
-
Exfiltration
ActivitySteal data before encryption.
EvidenceAnomalous outbound transfers.
TelemetryProxy/firewall.
Detection opportunityDetect bulk egress.
-
Impact
ActivityEncrypt and extort (T1486).
EvidenceMass encryption.
TelemetryFIM/EDR.
Detection opportunityAlert on rapid file changes.
Deep Technical Behavior Analysis
The defining behavior is double extortion that pairs encryption with leak threats. The strongest defenses are offline backups (reducing leverage), egress detection for pre-encryption theft, and behavioral ransomware detection.
Specific indicators are not fully specified in the source material and require validation.
Indicators of Compromise
Indicators of Behavior
Behavioral indicators to hunt for even when atomic IoCs are limited (Potential — validate against your baseline).
| Behavioral Indicator | Description | Data Source | Confidence |
|---|---|---|---|
| Anomalous PowerShell execution | Encoded/obfuscated commands, download cradles, or unusual parent-child process lineage. | Sysmon EID 1, PowerShell 4104 | Potential |
| Suspicious child process lineage | Office or web/service processes spawning script hosts or shells. | Sysmon EID 1, EDR | Potential |
| Security log clearing | Event log cleared or audit policy changed to hinder visibility. | Windows Security 1102, 4719 | Potential |
| New service / scheduled task creation | Unexpected persistence via services or tasks. | Security 7045, 4698; Sysmon | Potential |
| Beaconing to rare destinations | Periodic outbound connections to newly-seen domains/IPs or direct-IP C2. | Proxy, firewall, DNS logs | Potential |
| Unusual DNS queries | High-entropy or rare domains; possible tunneling. | DNS resolver logs | Potential |
| Authentication anomalies | Spraying/stuffing, impossible travel, or MFA fatigue patterns. | IdP/VPN logs, Azure AD/Okta sign-ins | Potential |
Detection Engineering Guidance
Defensive detection logic (Potential — tune to your environment). No exploit code is included; logic is for hunting and alerting only.
pseudo: periodic outbound (low jitter) to newly-seen domain/IP
with small uniform payloads => alert(level=medium)
pseudo (SIEM): count(file.action in [rename,modify] by host) over 1m > 200
and file.extension changes to uncommon/random => alert(level=critical)
Recommended Log Sources
| Platform | Log Source | What to Look For | Priority |
|---|---|---|---|
| Windows | Security Event Log | Logon (4624/4625), service (7045), task (4698), log clear (1102) | High |
| Windows | Sysmon | Process creation (1), network (3), image load (7), LSASS access (10) | High |
| Windows | PowerShell Operational | Script block logging (4104), module logging | High |
| Endpoint | EDR / Defender telemetry | Process tree, persistence, tamper attempts | High |
| Identity | IdP / VPN logs | Impossible travel, spraying, MFA fatigue | High |
| Network | DNS resolver logs | Rare/high-entropy domains, tunneling | Medium |
| Network | Proxy / firewall logs | Beaconing, direct-IP C2, exfil volume | High |
MITRE ATT&CK Mapping
| Tactic | Technique ID | Technique Name | Relevance | Detection Opportunity | Confidence |
|---|---|---|---|---|---|
| C2 | T1071 | Application Layer Protocol | Utilizes application layer protocols for communication with command and control servers. | Monitor outbound traffic for known protocol signatures. | Reported |
| Impact | T1486 | Data Encrypted for Impact | Encrypts files to render them inaccessible to users. | File integrity monitoring can detect changes in file states. | Reported |
Incident Response Guidance
- Validate exposure and confirm whether the issue applies to your environment.
- Preserve evidence (memory, disk, relevant logs) before remediation.
- Isolate affected hosts/accounts if compromise is suspected.
- Collect volatile data and review the log sources listed above.
- Hunt for the indicators of behavior and any related atomic indicators.
- Rotate potentially exposed credentials, keys, and session tokens.
- Remove persistence (tasks, services, keys, web shells, cron, OAuth grants).
- Patch affected systems; reimage where integrity cannot be assured.
- Run post-remediation validation and a BAS/security-validation retest.
Remediation and Hardening
- Patch affected systems and reduce internet-exposed services.
- Enforce MFA and least-privilege for privileged and remote access.
- Improve endpoint telemetry (Sysmon/EDR) and PowerShell logging.
- Restrict script execution and constrain LOLBins where feasible.
- Monitor persistence locations and disable unnecessary services.
- Segment critical assets and review privileged accounts.
- Rotate secrets and remove credentials from configuration files.
- Tune SIEM/EDR detections, then validate controls after changes.
Business Risk
- Service disruption: degraded or unavailable systems during compromise or recovery.
- Data exposure: risk to sensitive, regulated, or customer data depending on scope.
- Regulatory exposure: potential breach-notification and compliance obligations.
- Financial impact: incident response, downtime, and potential extortion costs.
- Brand and trust impact: reputational damage with customers and partners.
- Operational continuity: ransomware can halt critical business processes until restored.
- Identity blast radius: compromised accounts can expand access across cloud and SaaS.
Executive Takeaway
What leadership needs to know: Double extortion maximizes payment pressure by combining encryption with threatened data exposure. Current assessed risk: High.
Prioritise: patching/exposure reduction, identity hardening (MFA, least privilege), and detection coverage for the techniques above.
Validate after remediation: re-test controls with breach & attack simulation to confirm the relevant techniques are now prevented or detected.
Validating Your Defenses with Valitrix
The Valitrix BAS platform plays an essential role in helping organizations validate their defenses against ransomware threats like those posed by UNKN. By simulating real-world attack techniques mapped to the MITRE ATT&CK framework, Valitrix enables security teams to identify weaknesses in their defenses proactively. The platform emulates techniques such as double extortion, allowing teams to test their detection and response capabilities without risking operational environments.
This continuous validation process equips organizations with insights into their security posture, ensuring that defensive measures are not only in place but effective against evolving threats. By understanding how adversaries operate, organizations can better fortify their defenses against future attacks.
Key Takeaways
- Daniil Maksimovich Shchukin, known as UNKN, led the GandCrab and REvil ransomware gangs.
- The gangs employed double extortion tactics, significantly increasing their ransom success rates.
- Over $2 billion was extorted from victims by GandCrab before its shutdown in 2019.
- Organizations should adopt robust cybersecurity measures including regular backups and advanced endpoint protection.
Frequently Asked Questions
Who is UNKN?
UNKN is the alias of Daniil Maksimovich Shchukin, a Russian hacker involved in leading the GandCrab and REvil ransomware gangs.
What is double extortion?
Double extortion is a ransomware strategy where attackers encrypt data and threaten to publish it unless a ransom is paid.
What can organizations do to protect themselves from ransomware?
Organizations should implement regular backups, train employees on cybersecurity awareness, deploy advanced endpoint protection, and segment their networks to prevent ransomware spread.



