Germany Doxes “UNKN,” Head of RU Ransomware Gangs REvil, GandCrab
2026-04-07T01:23:42Z•6fa5b600ac6870e7d3145e2264563b4ff7168d94c234c4a183dba7d7173efea7
AI assistantsAisuruCanisterWormDDoSGandCrabI2PIoT botnetIranIran-backed actorsJackSkidKimwolfMFA bypassMicrosoftMossadPatch TuesdayREvilStarkillerStrykercloud securitydoxingphishing-as-a-serviceransomwarevulnerabilitieswiperzero-day
What happened
KrebsOnSecurity roundup of active, high-impact cyber threats and mitigations: German authorities identified and doxed Daniil Maksimovich Shchukin (alias “UNKN”), alleged leader of GandCrab and REvil. A financially motivated group unleashed “CanisterWorm,” a cloud-spreading worm/wiper targeting systems using Iran time zone or Farsi locale and combining theft/extortion with destructive wiping. U.S., Canadian and German authorities disrupted infrastructure for four massive IoT botnets (Aisuru, Kimwolf, JackSkid, Mossad) that had compromised >3 million devices and facilitated record DDoS attacks;
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- 6fa5b600ac6870e7d3145e2264563b4ff7168d94c234c4a183dba7d7173efea7
- Enrichment time
- 2026-04-07T01:23:42Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.