DoppelPaymer Continues to Cause Grief Through Rebranding
ID: 0435c03a-1505-5ddc-b997-f9ee6f4ff68f
STIX ID: report--0435c03a-1505-5ddc-b997-f9ee6f4ff68f
Feed Name: Zscaler Security Research Blog
This report documents the emergence of Grief (aka Pay or Grief) as a rebranded variant of DoppelPaymer ransomware: the leak and ransom portals are nearly identical with cosmetic changes, the malware shares core cryptography (2048-bit RSA, 256-bit AES) and much of the same codebase with only minor modifications (e.g., removed embedded ProcessHacker binaries, RC4 key length increase), and the actors switched to Monero for payments; the report includes multiple SHA256 IOCs and detection guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
