Germany Doxes 'UNKN,' Head of RU Ransomware Gangs REvil, GandCrab (krebsonsecurity.com)
- Reference: 0181388048
- News link: https://yro.slashdot.org/story/26/04/06/1644212/germany-doxes-unkn-head-of-ru-ransomware-gangs-revil-gandcrab
- Source link: https://krebsonsecurity.com/2026/04/germany-doxes-unkn-head-of-ru-ransomware-gangs-revil-gandcrab/
> An elusive hacker who went by the handle "UNKN" and ran the early Russian ransomware groups GandCrab and REvil [1]now has a name and a face . Authorities in Germany say 31-year-old Russian Daniil Maksimovich Shchukin headed both cybercrime gangs and helped carry out at least 130 acts of computer sabotage and extortion against victims across the country between 2019 and 2021. Shchukin was named as UNKN (a.k.a. UNKNOWN) in [2]an advisory published by the German Federal Criminal Police (the "Bundeskriminalamt" or BKA for short). The BKA said Shchukin and another Russian -- 43-year-old Anatoly Sergeevitsch Kravchuk -- extorted nearly $2 million euros across two dozen cyberattacks that caused more than 35 million euros in total economic damage.
>
> Germany's BKA said Shchukin acted as the head of one of the largest worldwide operating ransomware groups GandCrab and REvil, which pioneered the practice of double extortion -- charging victims once for a key needed to unlock hacked systems, and a separate payment in exchange for a promise not to publish stolen data. Shchukin's name appeared in a [3]Feb. 2023 filing (PDF) from the U.S. Justice Department seeking the seizure of various cryptocurrency accounts associated with proceeds from the REvil ransomware gang's activities. The government said the digital wallet tied to Shchukin contained more than $317,000 in ill-gotten cryptocurrency.
The BKA believes Shchukin resides in Krasnodar, Russia, where he is from. "Based on the investigations so far, it is assumed that the wanted person is abroad, presumably in Russia," the BKA advised. "Travel behavior cannot be ruled out."
[1] https://krebsonsecurity.com/2026/04/germany-doxes-unkn-head-of-ru-ransomware-gangs-revil-gandcrab/
[2] https://www.bka.de/DE/IhreSicherheit/Fahndungen/Personen/BekanntePersonen/CC_BW/DMS/Sachverhalt.html?nn=26874#detailinformationen265540
[3] https://krebsonsecurity.com/wp-content/uploads/2026/04/shchukin-seizure-revil.pdf
Re: (Score:3)
No, we speak English and bad English here. Is that like English NG?
-making sad typos when critiquing grammar or spelling is king of ironic, don't ya think?
Re: (Score:3)
> No, we speak English and bad English here. Is that like English NG?
>
> -making sad typos when critiquing grammar or spelling is king of ironic, don't ya think?
Jokes aside, I think the point is this isn't really a doxxing. Doxxing is an unauthorised release of personal information (usually with the intent to cause harm), this is really the opposite as it's a state releasing the name of a wanted criminal.
Re: (Score:2)
I've though about committing a crime before. When I do so, I'll consider Germany.
The problem is, all the good art and food is in Holland or France. What are you going to steal in Germany?
Re: (Score:2)
> Jokes aside, I think the point is this isn't really a doxxing. Doxxing is an unauthorised release of personal information (usually with the intent to cause harm), this is really the opposite as it's a state releasing the name of a wanted criminal.
No, I think it's a real doxxing. The German authorities know they have little chance of getting their hands on the crims themselves because Russia, but instead they release their identity (complete with photos) and expose them to the attention of interested parties in their own country. These may include other criminals looking to persuade them to share some of their several million Euros/Dollars in accumulated funds, possibly assisted by bolt cutters and a blow torch, and maybe the Russian government them
Finally! (Score:2)
They caught the villian that terrorized all those kids at the Willy Wonka Experience. Anyway, that's not a good business model. Don't pay either and when they leak it, download it and import the data back into your databases. Boom, solved. That and publicly torture them to death and see if other hackers think twice before doing this.