Skip to main content
Mallory
MalwareRansomwareUsed by 2 actors

Grief

Grief is a ransomware operation described in the provided content as having ties to the Russian cybercrime group Evil Corp and as an offshoot of DoppelPaymer, which itself evolved from Evil Corp. The group conducts double-extortion activity by stealing data and threatening to leak additional files unless an undisclosed ransom is paid. In the cited NRA incident, Grief posted the victim on its leak site, claimed to possess 13 files allegedly taken from NRA databases, and exposed material that reportedly included recent board meeting minutes, grant-related documents, and tax forms. The content also notes reporting that messaging around the NRA breach was amplified by a network of fake Twitter accounts, although public attribution did not establish that the network belonged to Grief. The group is reported to have spent much of 2021 targeting U.S. school districts and local governments, with additional attacks against government, healthcare, and education entities in states including New York, Alabama, Mississippi, Indiana, Washington, and Texas. Because of its reported Evil Corp lineage, ransom payments associated with Grief may carry U.S. sanctions risk. High-confidence behaviors directly mentioned in the content include operation of a public leak site, extortion through threatened publication of stolen data, and targeting of U.S. organizations including the National Rifle Association.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
EvilCorp

After the notorious Grief ransomware group added the National Rifle Association to its public list of victims, messages of the breach was reportedly amplified by a network of fake Twitter accounts.

via sc magazinescmagazine.com
Indrik Spider

The Grief ransomware gang -- which has ties to the prolific Russian cybercrime group Evil Corp -- posted about the NRA on its leak site... It threatened to leak more files if the NRA did not pay an undisclosed ransom.

via zdnet zero dayzdnet.com
MITRE ATT&CK

Techniques & procedures

2 distinct techniques documented for this family, organized by ATT&CK tactic.

Impact

2 techniques
T1486Data Encrypted for ImpactEvidence2
TacticImpact

The Grief ransomware gang -- which has ties to the prolific Russian cybercrime group Evil Corp -- posted about the NRA on its leak site... It threatened to leak more files if the NRA did not pay an undisclosed ransom.

T1657Financial TheftEvidence1
TacticImpact

Cybersecurity researchers began posting about the incident on Wednesday after Grief said it had 13 files allegedly from the NRA's databases... It threatened to leak more files if the NRA did not pay an undisclosed ransom.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping2

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.