Skip to main content
Mallory
Financially Motivated3 malware families

DOPPEL SPIDER

Also known asDOPPEL SPIDER

Doppel Spider is a financially motivated cybercriminal subgroup associated with the Russian-speaking Evil Corp ecosystem. The provided content states that Evil Corp split into Indrik Spider and Doppel Spider in 2019, with Doppel Spider operating a modified version of Dridex known as DoppelDridex and a variant of the BitPaymer ransomware known as DoppelPaymer. The group is linked to the use of Dridex as an initial access and reconnaissance tool preceding targeted ransomware operations. Reported activity includes exfiltration of tens of gigabytes of data, operation of a leak site with a countdown timer that increases ransom demands upon expiration, and deployment of DoppelPaymer ransomware. The content also notes public reporting that Doppel Spider stated unintentional infections against healthcare providers would be quickly resolved. Known alias in the provided content: doppel_spider.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal3

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.