Grief
Known to be a RaaS
Known to use a Captcha to block crawling.
Description
Grief, also known as Pay or Grief, is a ransomware group that emerged in May 2021 and is widely believed to be operated by actors linked to the Evil Corp cybercrime syndicate. It operates as a Ransomware-as-a-Service (RaaS) platform, using a double-extortion strategy: encrypting files while threatening to leak stolen data via its Tor-based leak site. Grief’s ransomware payload uses strong encryption (commonly RSA-2048 + AES-256) and typically appends the .grief extension to files. The group has targeted organizations across multiple sectors, including government, finance, education, and manufacturing, with a focus on U.S. and European entities. Grief has been associated with infrastructure and code overlaps from the earlier DoppelPaymer ransomware and uses phishing emails, malicious attachments, and compromised RDP credentials for intrusion. In late 2021, the U.S. Treasury’s OFAC issued sanctions against Grief due to its ties with Evil Corp, making ransom payments to the group legally risky for victims in the U.S.
External Analysis |
https://www.bleepingcomputer.com/news/security/grief-ransomware-linked-to-evil-corp-hackers/ |
https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-243a |
https://www.treasury.gov/news/press-releases/jy0333 |
https://www.trendmicro.com/en_us/research/21/i/grief-ransomware.html |
Urls |
Screen |
http://griefcameifmv4hfr3auozmovz5yi6m3h3dwbuqw7baomfxoxz4qteid.onion/ |
|
Chat servers |
Screen |
http://payorgz3j6hs2gj66nk6omfw65atgmqwzxqbbxnqi3bv2mlwgcirunad.onion/ |
|