Menu
Browse

Cyber Threat Actor: Grief

Aliases: 2 aliases
Actor Type Location Known Incidents
 Icon
Crime Syndicate
Russia
24 incidents
Profile

Grief, also known as PayorGrief, is a threat actor group that has been linked to Russia and is considered by some researchers to be a possible rebranding or evolution of the DoppelPaymer ransomware family. The group is publicly associated with the Evil Corp cybercrime syndicate, a Russian‑based organization that appears on the U.S. Treasury’s sanctions list, which complicates any ransom payment because transferring funds to a sanctioned entity is prohibited. These affiliations are the only attribution details explicitly stated in the available sources.

Grief has primarily targeted organizations in the education and healthcare sectors, as well as occasional targets in other industries such as food production, legal services, and municipal government. Reported incidents include ransomware attacks on K‑12 school districts in Virginia, Washington State, Texas and Mississippi, a dermatology and plastic surgery practice in Florida, a psychiatric and substance abuse provider in New York, and an orthopedic clinic in Indiana. The group’s activities involve deploying ransomware that encrypts systems and exfiltrating sensitive data, which is then used to demand payment under threat of public release or destruction.

The group's tactics involve gaining access to victim networks, exfiltrating data before or during encryption, and then publishing portions of the stolen information on a leak site to pressure victims into paying a ransom. Grief has adopted a double‑extortion model, threatening to release additional data if demands are not met, and has gone further by warning that it will destroy all stolen data if victims involve law enforcement or third‑party recovery firms. While the specific initial infection vectors are not detailed in the sources, the association with Evil Corp suggests the possible use of tools and techniques seen in DoppelPaymer and WastedLocker campaigns, such as credential harvesting and lateral movement via legitimate administrative utilities.

Representative operations that illustrate Grief's activity include the October 2021 ransomware attack on the National Rifle Association, during which tax documents and investment records were leaked as proof of the intrusion; the September 2021 breach of Greensville County Public Schools, where over 4,600 special‑education‑related PDFs were published; the June 2021 incident affecting a Florida dermatology and plastic surgery practice, in which financial and patient records were posted online; and the June 2021 compromise of Rehabilitation Support Services in New York, where several gigabytes of internal and client data were threatened for release. These examples show the group's pattern of targeting entities that hold valuable personal or financial information and then using the stolen data as leverage for extortion.

Incidents
Attributed incidents available to members
24 incidents
Sources
Sources available to members
199 sources