DoppelPaymer is a financially motivated ransomware operation and extortion group widely assessed as a Russia-based cybercriminal threat actor. Emerging in 2019 as a fork or offshoot of BitPaymer, it became associated with targeted enterprise intrusions, large ransom demands, and later double-extortion operations that combined file encryption with theft of unencrypted corporate data and threats to publish it on leak sites. The group has also been linked by multiple reports to the Grief rebrand. DoppelPaymer has targeted large organizations and public institutions across multiple countries, including energy, manufacturing, health care, government-related, construction, and automotive victims. Reported victims include major enterprises and hospitals, and the group was described as particularly active against Japanese entities during part of 2020. Operationally, DoppelPaymer is associated with human-operated intrusions that resemble broader big-game hunting ransomware tradecraft. Reported initial access and access-enablement paths include QAKBOT infections, SocGholish-delivered footholds, phishing, exposed remote services, compromised administrative credentials, and exploitation of internet-facing systems such as Citrix infrastructure. Once inside a network, the actors have been associated with credential abuse, privilege escalation, reconnaissance, lateral movement, persistence, and broad ransomware deployment using mechanisms such as PsExec, BITS jobs, scheduled tasks, and Group Policy-based distribution. Reporting also links DoppelPaymer intrusions with use of Cobalt Strike and PowerShell Empire during post-compromise operations. The ransomware operation has been documented changing local user passwords, establishing itself as a service, modifying boot configuration to facilitate execution, rebooting systems, and then encrypting files across victim environments. The group is also known for targeting backup infrastructure and using access to backup systems as leverage, including deleting backups and threatening exposure of backup-management credentials. DoppelPaymer adopted leak-site operations as part of double extortion and has publicly pressured non-paying victims by threatening or publishing stolen data. Known aliases include DoppelPaymer Ransomware Group and related operator references. The actor is best understood as a Russia-linked cybercriminal ransomware and extortion enterprise focused on high-value organizational victims for profit.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
26 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as one of several ransomware groups that used SocGholish infections as an entry point for follow-on attacks.
Previously involved in ransomware attacks targeting Foxconn.
Conducted a ransomware attack against a Foxconn plant in Ciudad Juárez and demanded a $34 million ransom.
Ransomware operation that claimed a prior attack on Foxconn's CTBG MX facility, demanding a $34 million ransom after alleged data theft, large-scale server encryption, and backup destruction.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.