SOCRadar reported a long-running phishing operation dubbed Operation DoppelBrand, attributed to a financially motivated actor tracked as GS7, that uses high-fidelity replicas of Fortune 500 and major consumer brands to harvest credentials and enable follow-on access. The activity observed most recently (Dec 2025–Jan 2026) impersonated major financial and technology organizations (including Wells Fargo, USAA, Navy Federal Credit Union, Fidelity, Microsoft, and Citibank) and relied on a highly automated domain and infrastructure pipeline, with researchers identifying hundreds of malicious domains and 150+ newly identified domains following consistent patterns. The operation is assessed as monetization-focused, with GS7 linked to trading stolen credentials and access in underground markets and using Telegram bots for credential handling/exfiltration; reporting also notes abuse of legitimate remote management tooling to help establish persistence after credential capture.
Dark Reading’s coverage of the SOCRadar findings emphasized the campaign’s effectiveness stemming from near-perfect portal impersonation and rapid infrastructure rotation, increasing the likelihood of successful credential theft against both enterprises and their customers. For defenders, the reporting highlights the need to treat this as an ongoing, scalable credential-harvesting and initial-access operation: prioritize monitoring for lookalike domains and brand-abuse infrastructure, strengthen anti-phishing controls around customer/employee authentication flows, and review remote management tool governance to reduce the impact of stolen credentials being converted into durable access.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
SOCRadar disclosed the Operation DoppelBrand campaign, attributed it to GS7, and assessed the actor likely operates as an initial access broker that may resell access to other criminal groups, including ransomware operators. The company also released TTPs and indicators of compromise to help defenders detect related activity.
After credential theft, the actor frequently installed legitimate remote monitoring and management tools such as LogMeIn, AnyDesk, and ScreenConnect through scripted loaders. This enabled persistent remote access on compromised systems.
As part of the campaign, harvested credentials and related victim telemetry were sent in real time to attacker-controlled Telegram bots. The operation also used traffic proxying and frequently rotated malicious domains to obscure backend infrastructure.
During the December 2025 to January 2026 activity window, the campaign impersonated organizations including Wells Fargo, USAA, Navy Federal Credit Union, Fidelity, Microsoft, and Citibank, with additional targeting across healthcare and telecommunications. Researchers noted a recent emphasis on English-speaking markets.
Between December 2025 and January 2026, the financially motivated actor GS7 conducted extensive phishing and brand-impersonation activity dubbed Operation DoppelBrand. The campaign used high-fidelity fake login portals and automated domain infrastructure to target Fortune 500 brands and their customers.
SOCRadar's infrastructure analysis found the actor tracked as GS7 had operated related phishing infrastructure over multiple years, with evolving TLD and registrar choices but consistent subdomain patterns and TLS fingerprints. Researchers identified nearly 200 related domains tied to the operation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.