Skip to content

Grief

Grief is a Windows ransomware family and double-extortion operation that emerged in May 2021 and is widely assessed to be a rebrand or direct successor of DoppelPaymer, itself closely linked to the BitPaymer lineage.

Profile source: Mallory opens in a new tab

Grief

Family profile

Grief is a Windows ransomware family and double-extortion operation that emerged in May 2021 and is widely assessed to be a rebrand or direct successor of DoppelPaymer, itself closely linked to the BitPaymer lineage. Reporting has repeatedly associated Grief with the Evil Corp and TA505 cybercrime ecosystem, although some affiliations are described as suspected rather than conclusively proven. The malware encrypts victim data and supports extortion through a public leak site used to pressure organizations by threatening publication of stolen files. Victimology has included government, education, healthcare, manufacturing, hospitality, information technology, pharmaceuticals, retail, agriculture, advanced technology, and other enterprise sectors across North America and Europe.

Technical analysis indicates Grief shares core code and operational infrastructure characteristics with DoppelPaymer, including closely related leak-site and negotiation-portal functionality and substantially similar cryptographic implementation. Documented differences include cosmetic rebranding, use of Monero in payment workflows, removal of some embedded tooling present in DoppelPaymer, and minor implementation changes such as modified string-encryption details. Grief samples have been observed using strong hybrid encryption consistent with the DoppelPaymer family.

Observed intrusions commonly place Grief late in the attack chain after earlier compromise activity involving Dridex and Cobalt Strike. Pre-encryption tradecraft has included DLL search order hijacking, signed binary proxy execution, masquerading, process injection, and abuse of relocated legitimate Windows binaries to load malicious DLLs from non-standard directories. During execution, Grief has been observed launched via rundll32 or regsvr32-style DLL registration workflows, modifying Windows services for persistence, altering boot configuration to impair recovery, changing Defender-related settings, and resetting ownership or permissions on files associated with backup or recovery software. Public reporting also notes that some analyzed cases did not observe shadow-copy deletion, meaning recovery opportunities may remain in certain incidents.

Grief should be understood as both a malware family and an extortion brand within a broader financially motivated intrusion ecosystem that has repeatedly rebranded to evade disruption, sanctions pressure, and public scrutiny.

Capabilities

  • Defense Evasion
  • Dll Sideloading
  • Exfiltration
  • Extortion
  • Persistence
  • Process Injection

Operational record

1
YARA rules
1
Ransom notes
1
Leak sites
0 available

Reported operators

Threat actors

4 named in public reporting
TA505

Threat Actor TA505 is also suspected of leveraging Grief Ransomware to carry out various campaigns/malicious activities.

DoppelPaymer Ransomware Group

The Grief Ransomware Gang (aka: PayOrGrief) claims to have infected 41 new victims between May 27, 2021—Oct. 1, 2021, with their ransomware.

Grief Ransomware Gang

The Grief Ransomware Gang (aka: PayOrGrief) claims to have infected 41 new victims between May 27, 2021—Oct. 1, 2021, with their ransomware.

INDRIK SPIDER

the new “Grief” ransomware startup was just the latest paintjob of DoppelPaymer, a ransomware strain that shared most of its code with an earlier iteration from 2016 called BitPaymer.

MITRE ATT&CK

Grief in ATT&CK

13 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.