Friday, June 13, 2025
HomeCyber Security NewsNew Version of GandCrab Ransomware Appends 5 Character Extension To Encrypted Files

New Version of GandCrab Ransomware Appends 5 Character Extension To Encrypted Files

Published on

SIEM as a Service

Follow Us on Google News

A new version of GandCrab Ransomware released, as like the previous version it was not distributed through exploit kits. The distribution method of GandCrab v5 is currently unknown, the new version appends a random 5 character extension on the encrypted files and creates HTML ransom note.

Gandcrab Ransomware is a widespread Ransomware, nowadays it evolves with newly updated futures under constant development to target various countries.

- Advertisement - Google News

The new version of GandCrab scan for all the computer and all the associated networks shares for files to encrypt.

Once it has the files it encrypts and then appends a random 5 character extension, “when I tested the ransomware it appended the .lntps extension to the encrypted file’s name, for example, test.doc has been encrypted and renamed to test.doc.lntps” wrote Lawrence Abrams.

After the encryption process, it creates an HTML ransom notes that shows files, documents, photos are encrypted and asks victim’s to pay the ransom to unlock the files.

Also, it contains instruction on how to reach the TOR payment site http://gandcrabmfe6mnef[.]onion and how to make the payment to buy grandcarb Decryptor to decrypt the encrypted files.

The ransom amount to be paid is $1200 through cryptocurrency DSH or Bitcoin, and the threat actors allowing 1 file to decrypt for free to show they can decrypt the encrypted files.

Ransomware is one of the fast Growing threat in worldwide and its considered as a leader of the Global cyber attack, in the first quarter of 2018 we came through only less number of ransomware attacks, but in the second quarter of 2018 and the ransomware returns back with new versions of GandCrab, Sigma, and GlobeImposter campaigns.

Gandcrab Ransomware Attack Windows Users via Compromised Websites

Hackers Launching GandCrab Ransomware via New Fallout Exploit Kit using Malvertising Campaign

GandCrab Ransomware Attack via Compromised Websites using SMB Exploit Spreader

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Major Outage Hits Google Cloud and Linked Cloudflare Services, Thousands Affected

On June 12, 2025, concurrent infrastructure failures at Cloudflare and Google caused widespread service...

TokenBreak Exploit Tricks AI Models Using Minimal Input Changes

HiddenLayer’s security research team has uncovered TokenBreak, a novel attack technique that bypasses AI...

WebDAV Remote Code Execution 0-Day Actively Exploited — PoC Released

A critical zero-day vulnerability in Microsoft’s Web Distributed Authoring and Versioning (WebDAV) protocol, tracked...

Cybercriminals Exploiting Expired Discord Invite Links to Deploy Multi-Stage Malware

Recent investigations by Check Point Research have uncovered a sophisticated malware campaign that leverages...

Credential Abuse: 15-Min Attack Simulation

Credential Abuse Unmasked

Credential abuse is #1 attack vector in web and API breaches today (Verizon DBIR 2025). Join our live, 15-min attack simulation with Karthik Krishnamoorthy (CTO - Indusface) and Phani Deepak Akella (VP of Marketing - Indusface) to see hackers move from first probe to full account takeover.

Discussion points


Username & email enumeration – how a stray status-code reveals valid accounts.
Password spraying – low-and-slow guesses that evade basic lockouts.
Credential stuffing – lightning-fast reuse of breach combos at scale.
MFA / session-token bypass – sliding past second factors with stolen cookies.

More like this

Major Outage Hits Google Cloud and Linked Cloudflare Services, Thousands Affected

On June 12, 2025, concurrent infrastructure failures at Cloudflare and Google caused widespread service...

TokenBreak Exploit Tricks AI Models Using Minimal Input Changes

HiddenLayer’s security research team has uncovered TokenBreak, a novel attack technique that bypasses AI...

WebDAV Remote Code Execution 0-Day Actively Exploited — PoC Released

A critical zero-day vulnerability in Microsoft’s Web Distributed Authoring and Versioning (WebDAV) protocol, tracked...