GandCrab Ransomware Developers Release Decryption Keys for Syrian Victims

Last updated November 8, 2018
Written by:
Nitish Singh
Image Courtesy of The Digital Artist

With the political and economic situation in Syria being at an all-time low, creators of the GandCrab malware have released the required keys to an underground forum. The developers of the malware released the keys shortly after a Syrian victim posted that he lost photos of his deceased children due to the encrypting malicious code.

Developers of the GandCrab malware released a public message stating that the “political and economic situation as well as relations with CIS countries” were the primary reasons for releasing the keys. They also revealed that they are making an exception and will not be sharing keys or ceasing operations regardless of any future circumstances going forward. The malware operators revealed that it was a mistake to keep Syria as one of the targeted countries. However, it is unknown if future malware campaigns will include Syria as one of the target countries because the latest version of the malware does not list Syrian languages as exceptions.

GandCrab Forum Post

Image Courtesy of GandCrab

The batch of keys released by the GandCrab developers will work only on systems that have affected Syrian victims. A number of security companies like BitDefender and ESET Security have published decryption tools that work on all known versions of the ransomware. 979 known Syrian victims are known to be affected, and the tools should work regardless of the version for all of the affected individuals.

It is not the first time that malware creators have released decryption keys with TeslaCrypt, Crysis and AESNI developers releasing their keys in the past. Using proper security tools and keeping an OS updated are two fundamental measures one can take to prevent being affected by ransomware.

What do you think about the GandCrab developers releasing decryption keys? Let us know in the comments below. Also, to get instant tech updates, follow TechNadu’s Facebook page, and Twitter handle.



For a better user experience we recommend using a more modern browser. We support the latest version of the following browsers: For a better user experience we recommend using the latest version of the following browsers: