Grief, also known as Pay or Grief, is a Windows ransomware family and double-extortion operation that emerged in May 2021 as a rebranding and continuation of DoppelPaymer. It retains much of DoppelPaymer’s core code, including file-encryption algorithms using 256-bit AES and 2048-bit RSA, import hashing, and encrypted-string handling. Its operators combine file encryption with theft of sensitive information, threatening to publish stolen data on a public leak site unless victims pay. Grief’s negotiation infrastructure closely resembles DoppelPaymer’s, but requests ransom payments in Monero rather than Bitcoin.
Observed Grief deployments frequently follow Dridex infections and Cobalt Strike activity. These precursor intrusions use techniques such as DLL search-order hijacking and process injection before the ransomware is launched. An analyzed Grief payload executed through a legitimate Windows utility, encrypted files, altered filesystem permissions and services, modified Windows Defender settings, disabled Windows recovery, and configured minimal Safe Mode boot. It also changed permissions on files associated with Veritas backup and recovery products, displayed a ransom message at logon, and established persistence by modifying an existing Windows service to execute the ransomware on subsequent boots. Grief uses RC4-encrypted strings and retains substantial implementation overlap with DoppelPaymer.
The operation has targeted organizations across multiple countries and sectors, including education, government, healthcare, manufacturing, hospitality, information technology, pharmaceuticals, agriculture, and retail. Its extortion activity has included attacks against U.S. school districts and local governments and publication of stolen organizational documents.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Threat Actor TA505 is also suspected of leveraging Grief Ransomware to carry out various campaigns/malicious activities.
The Grief Ransomware Gang (aka: PayOrGrief) claims to have infected 41 new victims between May 27, 2021—Oct. 1, 2021, with their ransomware.
The Grief Ransomware Gang (aka: PayOrGrief) claims to have infected 41 new victims between May 27, 2021—Oct. 1, 2021, with their ransomware.
the new “Grief” ransomware startup was just the latest paintjob of DoppelPaymer, a ransomware strain that shared most of its code with an earlier iteration from 2016 called BitPaymer.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
msinfo32.exe loads a malicious DLL from the appdata\roaming directory that masquerades as a legitimate DLL ( mfc42u.dll ). (T1036.005 Masquerading: Match Legitimate Name or Location)
This is likely the result of a Cobalt Strike Beacon injecting code into svchost.exe (T1055 Process Injection).
sbtbku~1.dll also modified the Windows LegalNoticeCaption and LegalNoticeText registry keys (T1112 Modify Registry), enabling them to display a ransom message customized to each victim environment immediately at logon.
if we see professional negotiator from Recovery Company™ - we will just destroy the data... they will delete the victim's decryption key, making it impossible to recover their files.
The Grief Ransomware Gang ... claims to have infected 41 new victims ... with their ransomware.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware family mentioned as one of several Evil Corp branding iterations in background context.
Grief is described as the latest version of DoppelPaymer ransomware with minor code changes and a new cosmetic theme. It uses largely the same codebase, ransom portal concepts, and encryption approach, while switching ransom payments to Monero and using GDPR-themed pressure tactics against victims.
A ransomware-extortion threat group/malware operation that maintains a public leak site and is suspected in the content to be leveraged by TA505.
Ransomware described as a continuation of the DoppelPaymer operation and a suspected predecessor to Entropy. The Entropy rebranding relationship remains unconfirmed in this reference.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.