The Grief ransomware operation emerged as a rebrand of DoppelPaymer, continuing the group’s double-extortion model of stealing data before encrypting systems and threatening publication on leak sites if victims refuse to pay. Earlier DoppelPaymer activity had already shown this approach through its public "Dopple Leaks" site, where operators exposed allegedly stolen victim data to increase pressure, reinforcing that these incidents should be treated as both ransomware attacks and data breaches.
Intrusions tied to Grief commonly chained Dridex infections with Cobalt Strike post-exploitation activity before ransomware deployment. Researchers observed attackers abusing DLL search order hijacking, masquerading, process injection, and signed binary proxy execution, including relocating legitimate Windows binaries to load malicious DLLs and using rundll32.exe to launch payloads that altered services, boot settings, registry keys, and Microsoft Defender protections. In some cases, the malware used bcdedit.exe to disable recovery and force safe mode boot, while changing service ImagePath values for persistence; analysts also noted that shadow copies were not always deleted, leaving a possible recovery path for some victims.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
Red Canary said Grief was first observed in May 2021 as a double-extortion ransomware operation. The report also noted external observations that Grief may be a rebrand of DoppelPaymer.
A South African logistics and supply chain company listed on DoppelPaymer's leak site was said to have been encrypted on January 20, 2020, with a ransom demand of 50 bitcoins.
BleepingComputer reported that Pemex was attacked by DoppelPaymer on November 10, 2019, and the attackers demanded 568 bitcoins for a decryptor.
Red Canary published technical analysis linking observed Grief intrusions with prior Dridex infections and Cobalt Strike activity, and described the ransomware's use of DLL hijacking, process injection, service modification, boot changes, Defender tampering, and ransom-note registry changes.
The operators of DoppelPaymer launched a public leak site called 'Dopple Leaks' to shame non-paying victims and publish files stolen before encryption. The site was described by the operators as being in 'test mode' and initially listed four alleged victims.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
zscaler.com
Open sourceredcanary.com
Open sourcebleepingcomputer.com
Open sourcesecureworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.