DopplePaymer is a ransomware threat actor known for operating a leak site and using double-extortion tactics. The group steals victim data and then encrypts systems, using the threat of public disclosure to increase pressure during ransom negotiations. It commonly publishes small samples of stolen material first and may release larger datasets if a victim refuses to pay. DopplePaymer was among the ransomware gangs actively publicizing victim data on dedicated leak blogs during the 2020 expansion of public extortion operations. The actor has been linked to intrusions against enterprise and service-provider environments, including a reported compromise of Digital Management Inc. (DMI), a managed IT and cybersecurity services provider with government-related work. In that incident, the group claimed to have encrypted thousands of internal systems and exposed stolen corporate and project-related data, including material associated with NASA-related work, illustrating both operational impact and data-theft leverage. DopplePaymer fits the broader class of financially motivated ransomware operators that shifted from encryption-only attacks to combined encryption-and-leak pressure. High-confidence reporting in this context supports its use of data theft, extortion through public leak infrastructure, and post-compromise actions consistent with ransomware deployment and coercive negotiation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware group listed as actively leaking stolen victim files on its blog.
Conducting a ransomware and extortion operation against Digital Management Inc. (DMI), claiming to have breached and encrypted systems, stolen NASA-related files, and published sample data on a leak site to pressure the victim into paying.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.