CSIDB logo
Threat actor

EvilCorp

Attribution profile

Type
Crime Syndicate
Location
Russia
Known incidents
0 incidents
First seen
-
Last seen
-
Updated
2026-08-28 15:57
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

EvilCorp is a threat actor known by that alias and is identified as a Russian-based group that appears on the United States Treasury’s sanctions list. The actor has been linked in open-source reporting to the Grief threat actors, who are described by some analysts as a possible rebranding or evolution of the DoppelPaymer ransomware family. This connection suggests that EvilCorp may be associated with operations that exhibit characteristics of both Grief and DoppelPaymer activity.

Observations of Grief activity, which is thought to be part of EvilCorp, show a focus on the education sector in the United States, specifically targeting K‑12 school districts. Victims have included Greensville County Public Schools in Virginia, Clover Park School District in Washington State, Lancaster Independent School District in Texas, and Booneville School District in Mississippi. In these incidents the actors exfiltrated large volumes of special‑education‑related PDF files containing personal data such as names, addresses, phone numbers, and educational or psychological evaluations. The actors then threatened to destroy the stolen data if victims contacted law enforcement or engaged recovery firms, indicating a financially motivated extortion objective rather than pure espionage or disruption.

The tactics observed in the Grief campaigns involve ransomware‑style data theft, the use of a dark web leak site to publish victim names and threaten data release, and public statements aligning with the Ragnar_Locker threat actors regarding consequences for involving authorities or third‑party negotiators. These behaviors reflect an evolution of DoppelPaymer‑style extortion that emphasizes data leakage and destruction threats alongside traditional encryption ransom demands.

Attribution information publicly available describes EvilCorp as operating from Russia and being subject to Treasury sanctions, while the Grief subgroup is characterized as a possible offshoot of DoppelPaymer and is believed to be affiliated with EvilCorp. No public sources directly tie EvilCorp to state sponsorship beyond its Russian origin and sanction status, nor do they detail specific malware families or initial access vectors unique to EvilCorp itself.

Representative operations attributed to the Grief faction, and thus indicative of EvilCorp‑linked activity, include the breach of Greensville County Public Schools where 4,604 special‑education PDFs were leaked, and the subsequent targeting of additional school districts that resulted in the exposure of similar sensitive records. These campaigns illustrate the actor’s pattern of exfiltrating niche personal data, leveraging leak‑site pressure, and issuing destruction threats to compel payment.

No further details about EvilCorp’s internal structure, revenue, or broader geopolitical aims are provided in the source material, and any assertions beyond those explicitly documented would constitute speculation. The profile therefore remains confined to the verified alias, geographic origin, sanction status, the alleged association with Grief, and the observed targeting and tactics of that subgroup as reported in open sources.

Incidents

Attributed incidents are available to members.

0 incidents
CSIDB