News Ababil.
Explore
SYS_NODE: ONLINE // Cyber Security

German Police Unmask UNKN Ransomware Leader Behind REvil and GandCrab

DECRYPTED BY: Isla Thorne | TIMESTAMP: 2026-05-04 T 04:03:02 Z | [ 1 MIN READ ]
2 Min Read
Share

UNKN ransomware leader identified by German authorities

The Federal Criminal Police Office (BKA) has linked 31‑year‑old Russian Daniil Maksimovich Shchukin to the moniker UNKN, the figure who steered the notorious REvil and GandCrab ransomware operations.

Investigators say Shchukin, together with 43‑year‑old Anatoly Sergeevich Kravchuk, extorted ↑ €2 million in ransom payments and caused economic damage exceeding ↓ €35 million between 2019 and 2021.

“We are a living proof that you can do evil and get off scot‑free,” the GandCrab farewell note read.

The U.S. Justice Department’s February 2023 filing revealed a cryptocurrency wallet tied to Shchukin held more than $317,000 in illicit proceeds.

From trash‑bins to billion‑dollar extortion

According to a Reuters report, the GandCrab affiliate model, launched in January 2018, paid hackers large cuts for compromising corporate networks, while REvil later refined the “double extortion” technique.

Law‑enforcement sources confirm Shchukin remains in Krasnodar, Russia, but his whereabouts are unverified; travel abroad cannot be excluded.

Cyber‑security analysts note the dismantling of REvil’s infrastructure after the July 2021 Kaseya attack marked a turning point, as the FBI released a universal decryption key.


Words by: Isla Thorne

Guest Technology Correspondent
(Note: Isla Thorne is covering this desk while Nova Stirling is recovering from the flu.)

Global Data Feed

More from this Intel

Crypto Clipper Campaign Exploits Fake Reviews, AI Narrators, and VirusTotal Comments

Crypto Clipper Campaign Exploits Fake Reviews, AI Narrators, and VirusTotal...

Jun 18, 2026
Inside The Gentlemen ransomware: Who Is Steering the Fast‑Growing RaaS Outfit?

Inside The Gentlemen ransomware: Who Is Steering the Fast‑Growing RaaS...

Jun 18, 2026
Lorem Ipsum malware adopts ClickFix delivery, new links to Vice Society revealed

Lorem Ipsum malware adopts ClickFix delivery, new links to Vice...

Jun 16, 2026
AI Deception Accelerates: How Defenders Can Harness Truth at Machine Speed

AI Deception Accelerates: How Defenders Can Harness Truth at Machine...

Jun 16, 2026
How Behavioral AI Thwarts Phishing and Account Takeovers – Webinar Insights

How Behavioral AI Thwarts Phishing and Account Takeovers – Webinar...

Jun 15, 2026
FBI Cracks AI-powered Phishing Service, Shuts Down Million-URL Network

FBI Cracks AI-powered Phishing Service, Shuts Down Million-URL Network

Jun 15, 2026

Join The Elite

Get the top 0.1% global intelligence and market insights delivered directly to your inbox before the masses.

We respect your privacy. No spam.