For years, he was a ghost. Known online as “Unkn” and later “UNKN,” the operator behind two of the most destructive ransomware operations in history moved through the cybercriminal underground with apparent impunity. He extorted hospitals, paralyzed meat processing plants, and helped extract hundreds of millions of dollars from victims worldwide. And now, German federal police say they know exactly who he is.
Germany’s Bundeskriminalamt (BKA) on April 30 issued an international arrest warrant and published the identity of Nikolay Gennadievich Golubev, a 36-year-old Russian national they allege is the mastermind behind the REvil and GandCrab ransomware gangs. The BKA simultaneously released photographs, known aliases, and last-known addresses — a classic doxing of a man long considered untouchable inside Russia’s borders. As Krebs on Security reported, the move represents one of the most aggressive public identification efforts by any Western law enforcement agency against a Russian cybercriminal suspect still believed to be living in Russia.
The timing is deliberate. It comes after years of painstaking digital forensics, cross-border intelligence sharing, and a series of arrests that slowly dismantled the networks surrounding Golubev. But the man himself remains free — almost certainly protected by geography and the longstanding reluctance of Russian authorities to extradite their own citizens for cybercrime.
GandCrab appeared in January 2018 and quickly became one of the most prolific ransomware-as-a-service operations ever seen. Its operators didn’t just encrypt victims’ files and demand payment. They built a franchise. Affiliates — essentially subcontractors — would deploy the malware and split the ransom proceeds with the core development team. The model was devastatingly effective. By the time GandCrab’s operators announced their “retirement” in mid-2019, they claimed to have collected over $2 billion in ransom payments, though independent researchers have suggested the true figure was likely lower but still staggering.
The retirement was a fiction.
Within weeks, a new ransomware strain called REvil — also known as Sodinokibi — emerged with code that bore unmistakable similarities to GandCrab. Security researchers at firms including Secureworks, Flashpoint, and Intel 471 quickly identified the technical overlap. Same encryption routines. Same affiliate infrastructure patterns. Same operational security habits. The consensus was clear: GandCrab hadn’t died. It had simply rebranded.
REvil went on to become arguably the most notorious ransomware operation of the early 2020s. Its victims included Travelex, the foreign exchange company brought to its knees in early 2020; JBS, the world’s largest meat processor, hit in May 2021; and most spectacularly, Kaseya, the IT management software provider whose compromise in July 2021 cascaded ransomware to as many as 1,500 downstream businesses in a single stroke. That last attack drew the direct attention of President Biden, who raised the issue with Russian President Vladimir Putin during a phone call and demanded action.
The figure known as Unkn was, according to German investigators and corroborating analyses from multiple cybersecurity firms, the central figure coordinating both operations. On Russian-language cybercrime forums like Exploit and XSS, Unkn recruited affiliates, negotiated terms, and enforced the gangs’ rules with an authority that suggested he was far more than a mere developer. He was the boss.
According to Krebs on Security, the BKA’s identification of Golubev relied on a combination of cryptocurrency tracing, operational security failures by the suspect, and intelligence gleaned from arrests of lower-ranking REvil affiliates. Several of those affiliates were apprehended in a coordinated international operation in late 2021 and early 2022, including Yaroslav Vasinskyi, a Ukrainian national arrested in Poland and later extradited to the United States, where he pleaded guilty to charges related to the Kaseya attack. Another, Yevgeniy Polyanin, was identified by the FBI but remains at large in Russia.
The German case appears to stem from REvil attacks on German companies and institutions, giving the BKA direct jurisdiction. German prosecutors have been notably aggressive in pursuing ransomware cases with a domestic nexus, and the public identification of Golubev fits a broader European strategy of naming and shaming suspects who cannot be physically arrested — imposing reputational and travel consequences even when criminal prosecution remains out of reach.
It’s a strategy born of frustration.
Russia has no extradition treaty with Germany, the United States, or any other Western nation. Article 61 of the Russian Constitution prohibits the extradition of Russian citizens to foreign states. And while Russian authorities did conduct a dramatic raid on alleged REvil members in January 2022 — reportedly at the request of U.S. law enforcement — the prosecutions that followed were widely seen as performative. Several suspects were released. The crackdown coincided with a brief thaw in U.S.-Russia relations that evaporated entirely after Russia’s full-scale invasion of Ukraine the following month.
So what does naming Golubev actually accomplish? More than it might seem at first glance. International arrest warrants restrict travel. They freeze assets in cooperating jurisdictions. They make it harder for the suspect to use banking systems or conduct business outside Russia. And they send a message to other cybercriminals: anonymity is not permanent.
The BKA released multiple photographs of Golubev, including what appear to be images from Russian social media profiles. They listed known aliases beyond Unkn, though several were redacted in the public-facing documents. His last confirmed address was in a mid-sized Russian city — details that Krebs on Security published but that this article withholds given ongoing operational sensitivities.
Cybersecurity researchers have been circling Golubev’s identity for years. On forums and in private Telegram channels frequented by threat intelligence analysts, speculation about Unkn’s real identity was a recurring topic. But the gap between suspicion and official attribution is vast. Germany’s willingness to put a name, face, and warrant behind those suspicions marks a significant escalation.
The REvil operation itself has been functionally dead since late 2021, when its Tor-based infrastructure was seized in a joint operation by the FBI, U.S. Cyber Command, and allied intelligence agencies. The group briefly attempted a comeback in early 2022 but was met with immediate skepticism from potential affiliates, many of whom suspected the revived infrastructure was compromised by law enforcement. The brand was burned.
But the people behind REvil didn’t vanish. Ransomware operators are remarkably resilient. They migrate to new groups, adopt new malware strains, and rebuild networks. Analysts at Recorded Future and Mandiant have noted that former REvil affiliates and developers have surfaced in connection with other prominent ransomware families, including BlackCat (also known as ALPHV) and more recently, newer operations that continue to evolve. Whether Golubev himself has continued active cybercriminal operations is unknown publicly, though German investigators’ decision to pursue the warrant now suggests they believe he remains a threat.
The broader context matters. Ransomware attacks against critical infrastructure have continued to escalate globally. The FBI’s Internet Crime Complaint Center reported that ransomware complaints increased again in 2025, with healthcare, manufacturing, and government entities among the most frequently targeted sectors. The total economic damage — including downtime, recovery costs, and ransom payments — runs into the tens of billions of dollars annually.
Governments have responded with an increasingly coordinated set of tools. The U.S. Treasury’s Office of Foreign Assets Control has sanctioned dozens of individuals and cryptocurrency wallets tied to ransomware. The Department of Justice has brought indictments against Russian, Ukrainian, and Chinese nationals. The EU has expanded its cyber sanctions regime. And intelligence agencies have conducted offensive cyber operations to disrupt ransomware infrastructure in real time — a capability that was once considered too escalatory but is now treated as routine.
Germany’s move against Golubev fits squarely within this playbook. It also reflects the growing importance of European law enforcement in the ransomware fight. Europol’s European Cybercrime Centre has coordinated multiple takedown operations, and agencies like the BKA, the Dutch National Police, and France’s ANSSI have developed world-class digital forensics capabilities. The days when ransomware investigations were an almost exclusively American affair are long over.
And yet the fundamental problem persists. The most dangerous ransomware operators live in countries that won’t arrest them. Russia, in particular, has maintained what amounts to a tacit non-aggression pact with its domestic cybercriminals: don’t target Russian organizations, and we won’t come after you. Some researchers have gone further, arguing that Russian intelligence services actively recruit from the cybercriminal talent pool, blurring the line between state-sponsored hacking and financially motivated crime.
Golubev’s case illustrates both the progress and the limits of international ransomware enforcement. The investigation that led to his identification was sophisticated, multinational, and years in the making. The evidence, according to the BKA’s public statements, is strong. But absent a dramatic change in Russian domestic politics or an unlikely lapse in judgment that takes Golubev to a country with an extradition treaty, he’s unlikely to see the inside of a courtroom.
That doesn’t make the warrant meaningless. It makes it a different kind of weapon — one aimed at constraining his future options rather than delivering immediate justice. Every border crossing becomes a risk. Every financial transaction outside Russia becomes traceable. Every associate now knows that Western intelligence has mapped the network.
For the victims of GandCrab and REvil — the hospitals that couldn’t access patient records, the small businesses that paid ransoms they couldn’t afford, the IT administrators who spent sleepless weeks rebuilding systems from scratch — the identification of the man allegedly responsible is a measure of accountability, however incomplete. The face behind the screen name. A name on a warrant.
Whether it leads to a prison cell remains an open question. But for Nikolay Golubev, the era of comfortable anonymity is over.


WebProNews is an iEntry Publication