DoppelPaymer ransomware operators used phishing emails, malicious attachments, and links to gain initial access, often chaining infections through Emotet and Dridex before deploying the final payload. After compromise, the attackers used tools including PowerShell Empire, Cobalt Strike, PsExec, and Mimikatz to steal credentials, move laterally, disable security controls, and prepare systems for encryption. The malware encrypted files on network, fixed, and removable drives, changed user passwords, rebooted systems into safe mode, and displayed a ransom note warning that stolen sensitive data could be leaked publicly.
The campaign disproportionately affected healthcare, emergency services, and education organizations, with reported incidents including a German hospital, a county E911 center, community colleges, and police and emergency services in a U.S. city. The activity highlighted a double-extortion model in which operational disruption was paired with data-theft pressure, while defenders were urged to harden email security, maintain offline backups, patch exposed systems, audit privileged accounts, monitor network traffic, enable 2FA, and enforce least-privilege access.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
The content says DoppelPaymer targeted another community college in September 2020. This is listed among the campaign's notable attacks on education-sector organizations.
The content states that DoppelPaymer also targeted a county E911 center in September 2020. This incident is presented as part of the ransomware's focus on emergency services organizations.
In September 2020, DoppelPaymer targeted a German hospital, disrupting communications and general operations. The incident is cited as a notable example of the group's impact on healthcare organizations.
The content says DoppelPaymer affected police and emergency services in a U.S. city in mid-2020. The incident is described as one of several attacks against critical public-sector targets.
The content states that DoppelPaymer was involved in attacks in 2020 and that one incident disrupted a community college. No more specific date is provided for this event.
In July 2019, DoppelPaymer actors infected 13 of 380 servers at a U.S. medical center and demanded 50 Bitcoin, worth about $600,000 at the time. The medical center needed several weeks to restore systems from offsite backups.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.