grief logo

grief

1 incidentes 0 paises 0 sectores ransomware RU Ultimo: 2026-06-25
Aliases: Pay OR Grief, DoppelPaymer, PayOrGrief
Ver en IntelTracker → APTTrail →
Grief is a ransomware group that emerged in May 2021 as a rebrand of the DoppelPaymer ransomware operation, which itself is believed to be an evolution of the BitPaymer ransomware. The group is associated with the threat actor designated as GOLD HERON and is assessed with moderate confidence to be affiliated with the Russian ransomware gang Evil Corp. Grief's primary motivation is financial gain, achieved through a multi-extortion model that encrypts victims' data and threatens its public release. A distinctive characteristic of Grief is its use of Monero cryptocurrency for ransom payments, consistent with its predecessor DoppelPaymer, and its aggressive tactic of threatening to delete decryption keys if victims engage with negotiation companies, law enforcement, or data recovery specialists.
Tecnicas MITRE
T1486, T1027, T1489, T1490

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises objetivo (SOCRadar)

United Arab EmiratesArgentinaAustriaAustraliaBarbadosBelgiumBahrainBrazilCanadaSwitzerland

Sectores objetivo (SOCRadar)

Construction of BuildingsFood ManufacturingOther Information ServicesRail TransportationReal EstateHospitalsEnterprises & HoldingAccommodationManufacturingConstruction

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com