Ransomware Group:  
Grief



Sponsored by Hudson RockUse Hudson Rock's free cybercrime intelligence tools to learn how compromised credentials are impacting your business


Sites | Yara Rules | Ransom Note(s) | Activity | Victims (3)

Doppelpaymer is a ransomware family that encrypts user data and later on it asks for a ransom in order to restore original files. It is recognizable by its trademark file extension added to encrypted files: .doppeled. It also creates a note file named: ".how2decrypt.txt".


Sites

Title Available Last Visit FQDN Screenshot
Grief list 🔴 2022-05-02 11:11:21.970076 griefcameifmv4hfr3auozmovz5yi6m3h3dwbuqw7baomfxoxz4qteid.onion N/A

Yara Rules

Ransom Note(s)

Activity over time

3 Victims

US flag

Booneville School District

Company logo


Discovery Date: 2021-06-30 00:00

Sector: Education Facilities

US flag

Lancaster Independent School District

Company logo


Discovery Date: 2021-06-09 00:00

Sector: Education Facilities

US flag

Clover Park School District

Company logo


Discovery Date: 2021-05-26 00:00

Sector: Education Facilities