GandCrab Ransomware Version 3 is now out

GandCrab version 3 was released, and the most noticeable change is the addition of a desktop background.
This new variant is distributed through exploit kits and malspam. The malspam emails have subjects like “Order #65121” and contain attachments with a VBS downloader that installs GandCrab v3.
Researchers discovered in a malware analysis that the most noticeable change in this release of GandCrab is the increment of the version number to 3, new ransom note text, and the introduction of a bad desktop background.
The ransom note is still named CRAB-DECRYPT.txt, and encrypted files still have the .CRAB extension.
This new variant of GandCrab also introduces a low-resolution background that tells the victim to read the CRAB-DECRYPT.txt ransom note.

Another change discovered is the implementation of a RunOnce autorun key that will cause GandCrab to start automatically when a user logs in. When GandCrab is installed, it will encrypt the computer, and then automatically reboot the computer. This version, also, introduces the domain “carder.bit” which is used as a C&C server.

Unfortunately, this version cannot be decrypted for free.
