Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ransomware-group-operationcybercrime-service-ecosystemenforcement-actionoperational-disruption

Germany Identifies Alleged REvil and GandCrab Leader Behind 130 Ransomware Attacks

Updated 3mo agoFirst seen Apr 6, 202618 sources

Germany's Federal Criminal Police Office (BKA) identified 31-year-old Russian national Daniil Maksimovich Shchukin as UNKN/UNKNOWN, the alleged leader and public face of the GandCrab and REvil ransomware operations, and named Anatoly Sergeevitsch Kravchuk, 43, as an alleged developer. Authorities said the pair were involved in ransomware activity from early 2019 through at least July 2021 and linked them to 130 attacks in Germany, including about 25 cases that generated roughly €1.9 million in ransom payments and caused more than €35 million in economic damage.

German investigators described GandCrab and REvil as highly organized ransomware-as-a-service enterprises that helped popularize double extortion and relied on affiliates, access brokers, malware obfuscation providers, and money-laundering support. REvil was among the most prolific ransomware groups, hitting major victims including JBS and Kaseya, before collapsing under mounting law-enforcement pressure after the FBI infiltrated its infrastructure; the gang briefly resurfaced before disappearing in late 2021, followed by affiliate arrests in Romania and a broader disruption announced by Russia's FSB in 2022.

Share:
Germany Identifies Alleged REvil and GandCrab Leader Behind 130 Ransomware Attacks
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

11 events from the most recent confirmed update back to the earliest known activity.

11 EVENTS
Apr 5, 20263mo ago

Germany's BKA identifies alleged REvil and GandCrab leaders

German authorities publicly identified 31-year-old Daniil Maksimovich Shchukin as the actor known as UNKN or UNKNOWN and 43-year-old Anatoly Sergeevitsch Kravchuk as a developer tied to REvil and GandCrab. The BKA alleged they were responsible for 130 ransomware attacks in Germany between 2019 and 2021.

Mar 30, 20263mo ago

German authorities announce further cybercrime enforcement success

German authorities announced an additional success in their fight against organized cybercrime in a case linked to alleged REvil/GandCrab actors. The notice represents a new official law-enforcement development preceding the later April 2026 public identification reporting.

LKA-BW: Weiterer Erfolg im Kampf gegen organisierte Cyberkriminalität: Mutmaßlicher ... | Presseportal
May 8, 20233y ago

Germany publicly identifies REvil figure 'UNKN'

A May 2023 report said German authorities publicly identified the actor known as UNKN, describing him as a leader tied to the REvil and GandCrab ransomware operations. The disclosure attributed the identification to German law enforcement reporting referenced by KrebsOnSecurity.

Germany Doxes “UNKN,” Head of RU Ransomware Gangs REvil, GandCrab - Infosec.Pub
Jan 1, 20233y ago

U.S. forfeiture filing names Shchukin in REvil proceeds case

A 2023 U.S. Justice Department forfeiture filing tied to REvil proceeds included Daniil Maksimovich Shchukin's name. The filing connected him to funds associated with the ransomware operation.

Jan 1, 20224y ago

Romanian authorities arrest REvil affiliates

After REvil's collapse, law enforcement actions included arrests of affiliates in Romania. These arrests were part of the wider crackdown on participants in the ransomware-as-a-service operation.

Russia's FSB announces arrests of REvil members

In January 2022, Russia's FSB said it had arrested several REvil members and disrupted the ransomware gang. This followed broader international efforts targeting the group's infrastructure and affiliates.

Oct 1, 20215y ago

REvil briefly resurfaces before ceasing operations

After going dark, REvil briefly returned online but had ceased operations by October 2021. Reports linked the shutdown to increasing pressure from investigators and prior infiltration of the group's servers by the FBI.

Jul 15, 20215y ago

REvil goes offline in mid-July 2021

The REvil ransomware operation went offline in mid-July 2021 amid mounting law enforcement pressure. Around this period, the actor known as UNKN reportedly disappeared from cybercrime forums and another figure, REvil/0_neday, became the group's public face.

Jul 1, 20215y ago

Kaseya attack accelerates pressure on REvil

In 2021, REvil's major attack on Kaseya intensified international law enforcement scrutiny of the group. The fallout from that incident was cited as part of the gang's subsequent decline.

Jan 1, 20197y ago

REvil and GandCrab operators conduct German ransomware attacks

Across roughly two dozen German cases, the suspects allegedly extorted about €1.9 million in ransom payments and caused more than €35 million in economic damage. The attacks were attributed to the GandCrab and later REvil ransomware-as-a-service operations.

REvil/GandCrab activity in Germany begins

German authorities said Daniil Maksimovich Shchukin and Anatoly Sergeevitsch Kravchuk were involved in GandCrab/REvil ransomware activity affecting Germany from at least early 2019. Investigators later tied them to 130 acts of computer sabotage and extortion in Germany between 2019 and 2021.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

17 LINKEDOpen in app
Organizations
6 linked
Recorded FutureKaseyaJBSKommersantKrebsOnSecurityIntel 471
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.