DoppelPaymer is Windows-targeting enterprise ransomware, generally characterized as a 2019 fork of BitPaymer that operated through a ransomware-as-a-service model. It encrypts data across compromised corporate environments and has been used in high-impact attacks against organizations in sectors including manufacturing, construction, automotive, healthcare, government, energy, and logistics. The malware is associated with double-extortion operations: operators steal confidential information before or alongside encryption, then threaten publication through a public leak site to coerce payment. DoppelPaymer operators have also targeted backup infrastructure, including by obtaining privileged access and deleting or accessing backups before ransomware deployment.
Observed DoppelPaymer intrusions have involved credential dumping with Mimikatz and lateral movement or broad ransomware deployment using PsExec, Cobalt Strike, and PowerShell Empire. An intrusion at a German hospital was linked to exploitation of CVE-2019-19781, followed by deployment of a loader and a dormant backdoor before encryption. DoppelPaymer has been linked in reporting to the DoppelSpider activity cluster, though public attribution remains less certain than its technical lineage. Activity declined in 2021 as operators transitioned to Grief, also known as Pay or Grief; the two ransomware variants share closely related code, encryption design, victim portal functionality, and leak-site infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Dabei handelte es sich um eine Lücke in der Citrix-VPN-Software, die unter dem Namen "Shitrix" bekannt wurde (CVE-2019-19781) ... Das wahrscheinlichste Szenario ist somit derzeit, dass die Cyberkriminellen die Shitrix-Lücke sehr bald nach ihrem Bekanntwerden und noch vor der Bereitstellung des Patches durch Citrix ausgenutzt haben. | So hätten die Angreifer eine Schadsoftware namens "DoppelPaymer" in das System geschleust. Dieser Verschlüsselungstrojaner sei bereits in zahlreichen anderen Fällen weltweit gegen Unternehmen und Institutionen ... eingesetzt worden.
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
CYFIRMA Researchers suspect this threat actor to be responsible for operating DoppelPaymer and DoppelDridex.
Cybersecurity researchers, including TRU, believe the Grief Group is merely a rebrand of the DoppelPaymer Ransomware Group.
Cybersecurity researchers, including TRU, believe the Grief Group is merely a rebrand of the DoppelPaymer Ransomware Group.
Dridex and their operators, also known as “Evil Corp,” continues to successful experimenting with targeted highly-impactful bank fraud and ransomware operations including working with such targeted ransomware variants as “BitPaymer” and “DoppelPaymer”.
The most active ransomware gang targeting Japanese entities appears to be the DoppelPaymer gang. The DoppelPaymer ransomware emerged in 2019 and is believed to have links with former members of the TA505 hacking group.
Doppel Spider opérerait lui une version modifiée de Dridex, DoppelDridex, ainsi qu’une variante du rançongiciel BitPaymer, DoppelPaymer.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
DoppelPaymer is an enterprise-targeting ransomware that compromises a corporate network, eventually gains access to admin credentials, and then deploys the ransomware on the network to encrypt all devices.
Erst jetzt, viele Monate später, haben sie diese Backdoor benutzt, um wieder Zugriff auf das Netz der Uni-Klinik zu erlangen.
Das wahrscheinlichste Szenario ist somit derzeit, dass die Cyberkriminellen die Shitrix-Lücke sehr bald nach ihrem Bekanntwerden und noch vor der Bereitstellung des Patches durch Citrix ausgenutzt haben. Sie sind dann darüber in das Netz der Uni-Klinik eingedrungen
DoppelPaymer uses a fairly sophisticated routine, starting off with network infiltration via malicious spam emails containing spear-phishing links or attachments designed to lure unsuspecting users into executing malicious code that is usually disguised as a genuine document.
DoppelPaymer uses a fairly sophisticated routine, starting off with network infiltration via malicious spam emails containing spear-phishing links or attachments designed to lure unsuspecting users into executing malicious code that is usually disguised as a genuine document.
DoppelPaymer is an enterprise-targeting ransomware that compromises a corporate network, eventually gains access to admin credentials, and then deploys the ransomware on the network to encrypt all devices.
Erst jetzt, viele Monate später, haben sie diese Backdoor benutzt, um wieder Zugriff auf das Netz der Uni-Klinik zu erlangen.
In early 2020, the following delivery mechanisms were seen – Group Policies ... – PsExec – BITS Jobs – Scheduled Tasks
The ransomware copies a legitimate service and replaces the original with a copy of itself
DoppelPaymer is an enterprise-targeting ransomware that compromises a corporate network, eventually gains access to admin credentials, and then deploys the ransomware on the network to encrypt all devices.
The ransomware copies a legitimate service and replaces the original with a copy of itself
such as the love of hiding RC4 encrypted strings using a 40 byte key that is reversed which is also used by Dridex and DoppelPaymer
With attackers leveraging the features that enable a user to execute processes on remote systems, PsExec can be abused for arbitrary command shell execution and lateral movement.
before encrypting devices on the network the attackers will first delete the backups so that they cannot be used to restore encrypted files.
“bestanden versleutelen” en “Single extortion: bestanden of systemen van het slachtoffer zijn versleuteld.”
DoppelPaymer has a crc32 list of processes and services it will terminate. If a process or service in its list is running, it will trigger the Process Hacker to terminate it.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
83 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only in related articles, not part of the main incident discussed.
Mentioned for comparison as a prominent ransomware family using similar extortion tactics.
Ransomware family previously distributed via SocGholish.
Named ransomware family deployed via SocGholish.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.