N/A The Evolution of GandCrab Ransomware Tamas Boczan https://www.youtube.com/watch?v=b57VV9BC6tEN/AThe vast majority of ransomware infections in the past years have been results of ransomware being sold as an easy-to-use service, following the Ransomware-as-a-Service (RaaS) model. In 2018, the RaaS-space was dominated by a new malware family: Gandcrab. We tracked and analyzed the family from the earliest stages to the latest version, observing differences between versions, like added features and rewritten functions. Besides the reverse-engineering of the payload, we analyzed the various distribution methods: drive-by downloads via exploit kits and different Javascript and Word doc droppers attached to spam e-mails. In this talk we present technical details of the different methods used to distribute the malware, highlight some interesting facts about the packer, and show the evolution of the malware payload.