Signal

German police identify leaders of REvil and GandCrab ransomware gangs

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-04-06 18:34 UTCUpdated 2026-04-07 09:24 UTC
rss
cveexploitsbreachesmalwarethreat_actorsadvisories
Source links open
Source links and full evidence are open here. Archive history, compare-over-time, alerts, exports, API, integrations, and workflow are paid.
No card needed for the free brief.
Evidence trail (top sources)
top sources (3 domains)domains are deduped. counts indicate coverage, not truth.
3 top sources shown
German Police Unmask REvil Ransomware Leader
SecurityWeek · News · securityweek.com · 2026-04-07 09:24 UTC
German authorities identify REvil and GangCrab ransomware bosses
bleepingcomputer_all · News · bleepingcomputer.com · 2026-04-06 23:54 UTC
German police unmask two suspects linked to REvil ransomware gang
The Record (Recorded Future News) · News · therecord.media · 2026-04-06 18:34 UTC
Overview

German Federal Police have unmasked two Russian nationals as the leaders behind the notorious GandCrab and REvil ransomware operations active between 2019 and 2021.

Entities
REvilGandCrabDaniil ShchukinAnatoly Kravchuk
Score total
1.32
Momentum 24h
3
Posts
3
Origins
3
Source types
1
Duplicate ratio
0%
Why now
  • The arrests come after investigations into ransomware operations from 2019 to 2021.
  • Recent law enforcement actions demonstrate increased focus on ransomware gangs.
  • Public identification of suspects raises awareness of ransomware threat actors.
Why it matters
  • Disrupting ransomware leadership can significantly reduce cyber extortion threats.
  • Identifying key actors aids international law enforcement collaboration.
  • Highlights ongoing efforts to combat major ransomware groups active in recent years.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: high
Recurring claims
  • Daniil Shchukin led the GandCrab and REvil ransomware operations and extorted over $2 million.
  • Anatoly Kravchuk worked as a developer for the REvil ransomware group.
How sources frame it
  • SecurityWeek: neutral
  • BleepingComputer: neutral
  • The Record: neutral
This report consolidates multiple sources confirming the identification of REvil and GandCrab ransomware leaders by German authorities, underscoring a key development in ransomware law enforcement efforts.
All evidence
All evidence
German Police Unmask REvil Ransomware Leader
SecurityWeek · securityweek.com · 2026-04-07 09:24 UTC
German authorities identify REvil and GangCrab ransomware bosses
bleepingcomputer_all · bleepingcomputer.com · 2026-04-06 23:54 UTC
German police unmask two suspects linked to REvil ransomware gang
The Record (Recorded Future News) · therecord.media · 2026-04-06 18:34 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 3Origin domains: 3Duplicates: -
Showing 3 / 0
Top publishers (this list)
  • SecurityWeek (1)
  • bleepingcomputer_all (1)
  • The Record (Recorded Future News) (1)
Top origin domains (this list)
  • securityweek.com (1)
  • bleepingcomputer.com (1)
  • therecord.media (1)