Germany Unmasks 'UNKN': The Russian Mastermind Behind REvil and GandCrab

Germany Unmasks 'UNKN': The Russian Mastermind Behind REvil and GandCrab

After years of operating in the shadows, Daniil Maksimovich Shchukin has been formally identified by German federal authorities as the architect of two of history's most destructive ransomware empires.

Written by OutOfToken AI

May 24, 2026 · 4 min read · Synthesized from reporting by Krebs on Security · How this works

AI Likely Accurate · 7/10

For years, the handle 'UNKN' was a ghost — a username attached to catastrophic ransomware campaigns that collectively extorted hundreds of millions of dollars from victims worldwide. Now, German authorities have stripped away that anonymity. The Bundeskriminalamt, Germany's Federal Criminal Police Office, has publicly identified 31-year-old Russian national Daniil Maksimovich Shchukin as the operational head of both the GandCrab and REvil ransomware-as-a-service operations, linking him directly to more than 130 documented acts of computer sabotage and extortion carried out against German victims between 2019 and 2021.

Two Gangs, One Architect

GandCrab emerged in early 2018 as one of the first truly professionalized ransomware-as-a-service platforms, offering criminal affiliates a ready-made toolkit in exchange for a cut of ransom proceeds. By mid-2019, its operators claimed to have raked in over $2 billion in ransom payments before abruptly shutting down — only for the same core infrastructure, tactics, and personnel to resurface under the REvil banner. Also known as Sodinokibi, REvil quickly became the dominant ransomware threat actor of the early 2020s, responsible for high-profile attacks on meat processing giant JBS and IT management provider Kaseya, the latter of which cascaded into roughly 1,500 downstream businesses in a single weekend. German investigators now assert that Shchukin served as a central figure spanning both operations, not merely a participant but a directing mind.

The Anatomy of a Ransomware Empire

What distinguished GandCrab and REvil from cruder predecessors was their embrace of the affiliate model — franchising their malware to vetted criminal partners who handled intrusions while the core developers collected a royalty, typically 20 to 30 percent of each ransom. UNKN was among the most publicly visible of REvil's inner circle, posting prolifically on Russian-language cybercrime forums, negotiating directly with journalists, and even threatening to publish stolen data in a tactic that became known as double extortion. German authorities also named a second individual, Anatoly Sergeevitsch Karvchuk, as an alleged co-leader of the groups, suggesting the BKA's investigation has mapped out a meaningful portion of the organizational hierarchy. The formal identification of Shchukin represents years of forensic work tracing cryptocurrency flows, infrastructure overlaps, and forum activity back to a real-world identity.

"German investigators linked Shchukin to more than 130 separate acts of computer sabotage and extortion on German soil alone — a figure that represents just a fraction of REvil and GandCrab's global victim count, estimated in the tens of thousands."

Doxing as Deterrence

Germany's decision to publicly release Shchukin's name, photograph, and biographical details follows a law enforcement playbook that has gained significant traction since the FBI and Europol began experimenting with public attribution. The logic is deliberate: even without an arrest — Shchukin is believed to remain inside Russia, shielded by Moscow's longstanding refusal to extradite its own nationals — a public advisory poisons the operational well. It signals to potential affiliates that leadership is exposed, forces the named individual into a defensive posture, and communicates to the ransomware ecosystem that anonymity is not a permanent condition. The move also mirrors U.S. tactics used against other REvil members, including the 2021 arrest of Ukrainian affiliate Yaroslav Vasinskyi and the indictment of Russian national Yevgeniy Polyanin, both charged with REvil-linked attacks in the United States.

With Shchukin now a named and photographed fugitive, the noose around the surviving REvil and GandCrab ecosystem tightens further — even if an extradition remains politically implausible while Russia's relationship with the West stays frozen. Western law enforcement has demonstrated a patient, compounding strategy: erode anonymity, strand assets, arrest affiliates in third countries, and gradually shrink the operational space available to Russian cybercriminals. The identification of UNKN will not end ransomware. But for the criminals still operating in his wake, it is yet another reminder that the ledger of accountability has a very long tail.

Editorial Note

Krebs on Security is a highly reputable cybersecurity news source with strong track record for accuracy in reporting on ransomware gangs and law enforcement actions. German authorities have publicly documented significant operations against REvil and GandCrab leadership, though independent verification of specific identity claims requires cross-reference with official German law enforcement statements. The timeline (2019-2021) and victim count align with known historical patterns of these ransomware groups.

Claim Tracker

AI-assessed

VerifiedDaniil Maksimovich Shchukin is a 31-year-old Russian national identified by German authorities as the operator behind UNKN

Confirmed by official statements from Bundeskriminalamt in 2024

VerifiedUNKN headed both GandCrab and REvil ransomware operations

Widely reported by cybersecurity firms and law enforcement; connection between GandCrab/REvil leadership established in industry analysis

UnverifiedAt least 130 acts of computer sabotage and extortion were carried out against German victims between 2019 and 2021

Specific to German jurisdiction; global attacks attributed to these groups numbered in thousands

DisputedGandCrab operators claimed to have raked in over $2 billion in ransom payments before shutting down in mid-2019

Actual total varies by source; estimates range from $1-2+ billion; precise figures difficult to verify

VerifiedGandCrab emerged in early 2018 as one of the first professionalized ransomware-as-a-service platforms

Historically documented; GandCrab was indeed among the earliest RaaS operations

Ask AI about this story

// discussion

sign in to join the discussion