DoppelPaymer is a ransomware and extortion operation widely associated with the Evil Corp cybercrime ecosystem and assessed to have Russian origins through that lineage. The group became known for high-impact intrusions against large enterprises, manufacturers, public-sector entities, universities, telecommunications providers, and critical-industry organizations. Reported victims include Foxconn, Compal, PEMEX, Newcastle University, Hall County, the City of Torrance, Delaware County, Banijay Group SAS, and Bretagne Télécom. Grief has been described as an offshoot or rebrand linked to DoppelPaymer, and reporting has also tied DoppelPaymer to the broader Evil Corp cluster. The operation used ransomware together with data theft and public leak pressure, making it one of the early major groups to adopt the double-extortion model after it gained prominence in the ransomware ecosystem. Operators maintained a leak site to publish stolen victim data when negotiations failed or to increase coercive pressure during negotiations. In notable incidents, DoppelPaymer claimed large-scale encryption of server estates, theft of corporate data, and destruction of backup data to hinder recovery. DoppelPaymer access has been linked to multiple upstream intrusion channels and malware ecosystems. Reporting indicates SocGholish/FakeUpdates infections were used as an entry point for DoppelPaymer operations, and QBot/Qakbot has also been associated with access used by the group. The actor’s tradecraft includes initial compromise through brokered or malware-enabled access, enterprise-wide deployment of ransomware, exfiltration of victim data, and efforts to impair recovery and defensive visibility. Observed behavior associated with the group includes disabling or tampering with security tooling, including abuse of legitimate rootkit-removal or antivirus-related drivers and tools to weaken endpoint protections. DoppelPaymer has targeted organizations in manufacturing and industrial environments, including electronics and oil and gas, and leaked data from such victims has reportedly exposed sensitive operational and engineering documentation. The group’s activity is financially motivated and centered on ransom extraction through encryption, stolen-data extortion, and public shaming.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as one of several ransomware groups that used SocGholish infections as an entry point for follow-on attacks.
Previously involved in ransomware attacks targeting Foxconn.
Conducted a ransomware attack against a Foxconn plant in Ciudad Juárez and demanded a $34 million ransom.
Ransomware operation that claimed a prior attack on Foxconn's CTBG MX facility, demanding a $34 million ransom after alleged data theft, large-scale server encryption, and backup destruction.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.