News Ababil.
Explore
SYS_NODE: ONLINE // Cyber Security

German Police Unmask UNKN Ransomware Leader Behind REvil and GandCrab

DECRYPTED BY: Isla Thorne | TIMESTAMP: 2026-05-04 T 04:03:02 Z | [ 1 MIN READ ]
2 Min Read
Share

UNKN ransomware leader identified by German authorities

The Federal Criminal Police Office (BKA) has linked 31‑year‑old Russian Daniil Maksimovich Shchukin to the moniker UNKN, the figure who steered the notorious REvil and GandCrab ransomware operations.

Investigators say Shchukin, together with 43‑year‑old Anatoly Sergeevich Kravchuk, extorted ↑ €2 million in ransom payments and caused economic damage exceeding ↓ €35 million between 2019 and 2021.

“We are a living proof that you can do evil and get off scot‑free,” the GandCrab farewell note read.

The U.S. Justice Department’s February 2023 filing revealed a cryptocurrency wallet tied to Shchukin held more than $317,000 in illicit proceeds.

From trash‑bins to billion‑dollar extortion

According to a Reuters report, the GandCrab affiliate model, launched in January 2018, paid hackers large cuts for compromising corporate networks, while REvil later refined the “double extortion” technique.

Law‑enforcement sources confirm Shchukin remains in Krasnodar, Russia, but his whereabouts are unverified; travel abroad cannot be excluded.

Cyber‑security analysts note the dismantling of REvil’s infrastructure after the July 2021 Kaseya attack marked a turning point, as the FBI released a universal decryption key.


Words by: Isla Thorne

Guest Technology Correspondent
(Note: Isla Thorne is covering this desk while Nova Stirling is recovering from the flu.)

Global Data Feed

More from this Intel

CISA Flags Actively Exploited Linux Root Access Bug CVE-2026-31431 in KEV List

CISA Flags Actively Exploited Linux Root Access Bug CVE-2026-31431 in...

May 04, 2026
Russia Hacked Routers to Harvest Microsoft Office Tokens – Inside the Massive DNS Hijack

Russia Hacked Routers to Harvest Microsoft Office Tokens – Inside...

May 03, 2026
Microsoft Patch Tuesday April 2026: 167 Fixes, Zero‑Day Threats and AI‑Driven Surge

Microsoft Patch Tuesday April 2026: 167 Fixes, Zero‑Day Threats and...

May 02, 2026
Scattered Spider guilty plea: UK hacker Tylerb admits $8 million crypto theft

Scattered Spider guilty plea: UK hacker Tylerb admits $8 million crypto...

May 02, 2026
Christian Phone Network Launches with Mandatory Porn and Gender Content Blocks

Christian Phone Network Launches with Mandatory Porn and Gender Content...

May 01, 2026
PyTorch Lightning Supply Chain Attack Unveils Credential‑Theft Malware

PyTorch Lightning Supply Chain Attack Unveils Credential‑Theft Malware

May 01, 2026

Join The Elite

Get the top 0.1% global intelligence and market insights delivered directly to your inbox before the masses.

We respect your privacy. No spam.