Grief is a Windows ransomware family and double-extortion operation that emerged in May 2021 and is widely assessed to be a rebrand or direct successor of DoppelPaymer, itself closely linked to the BitPaymer lineage. Reporting has repeatedly associated Grief with the Evil Corp and TA505 cybercrime ecosystem, although some affiliations are described as suspected rather than conclusively proven. The malware encrypts victim data and supports extortion through a public leak site used to pressure organizations by threatening publication of stolen files. Victimology has included government, education, healthcare, manufacturing, hospitality, information technology, pharmaceuticals, retail, agriculture, advanced technology, and other enterprise sectors across North America and Europe.
Technical analysis indicates Grief shares core code and operational infrastructure characteristics with DoppelPaymer, including closely related leak-site and negotiation-portal functionality and substantially similar cryptographic implementation. Documented differences include cosmetic rebranding, use of Monero in payment workflows, removal of some embedded tooling present in DoppelPaymer, and minor implementation changes such as modified string-encryption details. Grief samples have been observed using strong hybrid encryption consistent with the DoppelPaymer family.
Observed intrusions commonly place Grief late in the attack chain after earlier compromise activity involving Dridex and Cobalt Strike. Pre-encryption tradecraft has included DLL search order hijacking, signed binary proxy execution, masquerading, process injection, and abuse of relocated legitimate Windows binaries to load malicious DLLs from non-standard directories. During execution, Grief has been observed launched via rundll32 or regsvr32-style DLL registration workflows, modifying Windows services for persistence, altering boot configuration to impair recovery, changing Defender-related settings, and resetting ownership or permissions on files associated with backup or recovery software. Public reporting also notes that some analyzed cases did not observe shadow-copy deletion, meaning recovery opportunities may remain in certain incidents.
Grief should be understood as both a malware family and an extortion brand within a broader financially motivated intrusion ecosystem that has repeatedly rebranded to evade disruption, sanctions pressure, and public scrutiny.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Threat Actor TA505 is also suspected of leveraging Grief Ransomware to carry out various campaigns/malicious activities.
The Grief Ransomware Gang (aka: PayOrGrief) claims to have infected 41 new victims between May 27, 2021—Oct. 1, 2021, with their ransomware.
The Grief Ransomware Gang (aka: PayOrGrief) claims to have infected 41 new victims between May 27, 2021—Oct. 1, 2021, with their ransomware.
the new “Grief” ransomware startup was just the latest paintjob of DoppelPaymer, a ransomware strain that shared most of its code with an earlier iteration from 2016 called BitPaymer.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
msinfo32.exe loads a malicious DLL from the appdata\roaming directory that masquerades as a legitimate DLL ( mfc42u.dll ). (T1036.005 Masquerading: Match Legitimate Name or Location)
This is likely the result of a Cobalt Strike Beacon injecting code into svchost.exe (T1055 Process Injection).
if we see professional negotiator from Recovery Company™ - we will just destroy the data... they will delete the victim's decryption key, making it impossible to recover their files.
The Grief Ransomware Gang ... claims to have infected 41 new victims ... with their ransomware.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware family mentioned as one of several Evil Corp branding iterations in background context.
Grief is described as the latest version of DoppelPaymer ransomware with minor code changes and a new cosmetic theme. It uses largely the same codebase, ransom portal concepts, and encryption approach, while switching ransom payments to Monero and using GDPR-themed pressure tactics against victims.
A ransomware-extortion threat group/malware operation that maintains a public leak site and is suspected in the content to be leveraged by TA505.
Named only as another ransomware group with similar API-based admin panel and leak site characteristics.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.