Doppel Spider is a financially motivated cybercriminal threat actor associated with the Evil Corp ecosystem and widely linked to targeted ransomware operations. The group emerged publicly around April 2019 as a subgroup or split from Evil Corp, alongside Indrik Spider, but reporting also indicates continued collaboration with Evil Corp rather than a fully separate organization. Doppel Spider is known for operating modified Dridex malware referred to as DoppelDridex and a BitPaymer-derived ransomware variant known as DoppelPaymer. The actor has also been associated with use of Emotet as a delivery service for its malware. Operationally, Doppel Spider fits the mature eCrime model in which initial malware access is leveraged for hands-on-keyboard intrusion and ransomware deployment against enterprise victims. Its activity includes use of Dridex-family tooling for initial access and post-compromise reconnaissance, followed by deployment of ransomware for monetization. The group has been reported to exfiltrate large volumes of victim data and to operate a leak site with escalating ransom pressure, indicating data-theft extortion in addition to encryption-based ransomware. Public reporting also places Doppel Spider among actors that publicly claimed they would avoid or remediate infections affecting healthcare providers, reflecting awareness of victim-sector sensitivity during 2020. Known tooling and malware associated with Doppel Spider include DoppelDridex, DoppelPaymer, BitPaymer lineage malware, and use of Emotet-delivered infection chains. The actor is part of the broader Russian-speaking cybercriminal milieu tied to Dridex and Evil Corp operations. High-confidence reporting supports characterization of Doppel Spider as an Evil Corp-linked ransomware subgroup specializing in enterprise intrusion, data exfiltration, and extortion.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
11 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed among detected threat actors/TTP references, but not substantively discussed in the report summary.
Named threat actor referenced in global threat reporting.
Doppel Spider is a group that split from Evil Corp in 2019, operating DoppelDridex and DoppelPaymer ransomware. It conducts both banking fraud and ransomware campaigns, sometimes publishing exfiltrated data from victims.
Splinter or sub-group linked to Evil Corp operating DoppelDridex and DoppelPaymer for both banking fraud and ransomware campaigns, including data leak extortion.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.