deathgrip
- First seen
- 2024-06-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Profile updated
- 2026-07-07 13:58:22
Targeted industries: education-and-nonprofits financial-services government-and-public-sector healthcare-and-pharmaceutical retail-and-hospitality
Context
DeathGrip is a Ransomware-as-a-Service (RaaS) that emerged around June 2024, offering malware payloads built with leaked LockBit 3.0 and Yashma/Chaos builders. Designed to lower technical barriers, it enables even low-skilled operators to deploy highly capable ransomware attacks. DeathGrip campaigns typically employ AES-256 encryption, delete shadow copies and recovery features, and modify system settings to hinder restoration. Earlier infections include low-tier ransom demands (e.g., around $100), reflecting entry-level targeting, though its flexible tooling allows a range of payload configurations.
Reports & references
- ransomlook.io — Deathgrip (report)
- Broadcom/Symantec — Deathgrip Emergence Of A New Ransomware As A Service (report)
- sentinelone.com — Deathgrip Raas Small Time Threat Actors Aim High With Lockbit Yashma Builders (report)
- enigmasoftware.com — Deathgripransomware Removal (report)
- pcrisk.com — 30382 Deathgrip Ransomware (report)