Long before ransomware attacks became a weekly headline, one malware family quietly rewrote the rules of cybercrime. GandCrab did not just extort victims, it built an entire business around extortion, complete with affiliate contracts, performance metrics, and customer service. Security researchers at McAfee dug into how the operation actually functioned, and what they found reads less like a hacking case study and more like a franchise agreement. Understanding GandCrab's structure matters today because the ransomware as a service model it helped popularize is still the dominant format behind modern attacks.
What Made GandCrab Different: An Affiliate Business Model
Most people imagine ransomware as the work of a single hacker planting malicious code. GandCrab operated differently. According to McAfee's analysis, the developers behind GandCrab did not carry out attacks themselves. Instead, they recruited affiliates who distributed the malware and handled the actual infections, while the core operators took a cut of the proceeds.
That cut was substantial: affiliates kept 70% of ransom payments, with the remainder flowing back to the developers who maintained the code. This revenue split incentivized affiliates to push volume, and it gave the operators a steady income stream without needing to touch a single victim's machine directly.
The arrangement also came with accountability. McAfee found that affiliates who underperformed were expelled from the program, a detail that underscores just how businesslike the operation had become. Low output meant termination, the same logic that governs any sales team measured on quotas. The malware itself was also engineered to skip machines located in Russia and other former Soviet states, a common pattern among ransomware groups believed to operate out of that region, likely to avoid drawing law enforcement attention at home.
The Technical Playbook: Encryption, Shadow Copy Deletion, and Proof-of-Decryption
Beneath the business structure sat a genuinely effective piece of malicious engineering. GandCrab combined AES and RSA encryption, layering symmetric and asymmetric cryptography so that victims could not simply reverse the process without the attacker's private key. Once files were locked, the malware deleted Windows shadow copies, the built-in backup snapshots that many users rely on to restore files after a system problem. Removing those copies closed off one of the easiest recovery paths available to victims who had not maintained separate offline backups.
To prove the ransom demand was legitimate rather than a bluff, the operators built in a mechanism to decrypt one file for free. This small gesture served a specific psychological purpose: it demonstrated that paying would actually restore access, making victims more likely to follow through with payment rather than write off their data as a total loss.
Dark-Web Support and Dash Payouts: Extortion as Customer Service
Perhaps the most unusual aspect of GandCrab's operation was how it treated victims once the ransom note appeared. The group offered dark-web support available around the clock, effectively running a help desk for people being extorted. Victims confused about payment steps or decryption instructions could get guidance, a service layer that made the entire process feel disturbingly close to legitimate customer support.
Payments themselves were funneled through Dash rather than the more commonly discussed Bitcoin. Dash offers faster transaction times and additional privacy features, which made it an appealing choice for an operation that needed to process payouts across a distributed affiliate network while limiting traceability.
What This Means for Your Security Stack Today
GandCrab is a useful case study precisely because the ransomware as a service model it refined never went away. Affiliate structures, tiered payouts, and dark-web support channels remain standard features of ransomware operations today. The Check Point report on 2,139 ransomware victims in Q2 2026 shows just how much this affiliate-driven approach has scaled, confirming that the playbook GandCrab helped establish continues to generate real victims at real volume.
For everyday users and small businesses, the defensive lessons are unchanged. Because ransomware like GandCrab deletes shadow copies to block easy recovery, offline and cloud backups stored separately from your main system are essential, not optional. Endpoint security tools that catch malicious encryption behavior before it completes a full pass through your files add another layer of protection. A reputable VPN will not stop ransomware on its own, but it reduces exposure on public networks and limits the kind of network snooping that sometimes precedes targeted attacks, particularly for remote workers and small business staff connecting from varied locations.
Actionable Takeaways
Back up your files regularly, and keep at least one copy offline or in storage the ransomware cannot reach through your network. Keep operating systems and security software updated, since many ransomware infections still exploit known, patchable vulnerabilities. Be skeptical of unsolicited attachments and links, since affiliate-driven campaigns rely heavily on volume-based phishing to find victims. Finally, treat any single security tool, whether a VPN, antivirus, or backup solution, as one piece of a layered defense rather than a complete answer. GandCrab proved that ransomware operators think like businesses; your defenses should be just as deliberate.




