deathgrip

First seen
2024-06-01 00:00:00
Malware type
ransomware
Family
Malware family
Profile updated
2026-07-07 13:58:22

Targeted industries: education-and-nonprofits financial-services government-and-public-sector healthcare-and-pharmaceutical retail-and-hospitality

Context

DeathGrip is a Ransomware-as-a-Service (RaaS) that emerged around June 2024, offering malware payloads built with leaked LockBit 3.0 and Yashma/Chaos builders. Designed to lower technical barriers, it enables even low-skilled operators to deploy highly capable ransomware attacks. DeathGrip campaigns typically employ AES-256 encryption, delete shadow copies and recovery features, and modify system settings to hinder restoration. Earlier infections include low-tier ransom demands (e.g., around $100), reflecting entry-level targeting, though its flexible tooling allows a range of payload configurations.

Reports & references

  • ransomlook.io — Deathgrip (report)
  • Broadcom/Symantec — Deathgrip Emergence Of A New Ransomware As A Service (report)
  • sentinelone.com — Deathgrip Raas Small Time Threat Actors Aim High With Lockbit Yashma Builders (report)
  • enigmasoftware.com — Deathgripransomware Removal (report)
  • pcrisk.com — 30382 Deathgrip Ransomware (report)

External references