← Back to Ransomware Tracker

Grief

Inactive
Doppelpaymer is a ransomware family that encrypts user data and later on it asks for a ransom in order to restore original files. It is recognizable by its trademark file extension added to encrypted files: .doppeled. It also creates a note file named: ".how2decrypt.txt".
3 Victims
May 26, 2021 First Discovered
Jun 30, 2021 Last Discovered
1723 Days Inactive
0% Infostealer
0/1 Sites Online
Top Countries
US 3
Top Sectors
Education Facilities 3
Known Locations (1)
Grief list
griefcameifmv4hfr3auozmovz5yi6m3h3dwbuqw7baomfxoxz4qteid.onion
Intelligence
Victims (3)
Booneville School District
US Education Facilities Discovered: Jun 30, 2021 · Attack est.: Jun 30, 2021
Lancaster Independent School District
US Education Facilities Discovered: Jun 9, 2021 · Attack est.: Jun 9, 2021
Clover Park School District
US Education Facilities Discovered: May 26, 2021 · Attack est.: May 26, 2021