DoppelPaymer is a financially motivated ransomware operation and extortion gang widely assessed to be based in Russia or the Russian Federation. It emerged in 2019 as a fork or offshoot of BitPaymer and became associated with targeted enterprise intrusions against large organizations, including companies, hospitals, universities, manufacturers, and government-related entities. Known aliases include doppelpaymer, doppelpaymer_gang, DoppelPaymer ransomware operators, and related operator designations. The group is known for big-game hunting and double-extortion operations. In addition to encrypting systems, DoppelPaymer operators have stolen unencrypted data and threatened to publish it on leak infrastructure when victims refused to pay. The operation maintained a leak site and victim negotiation portals, and its public leak activity helped normalize data-theft extortion across the ransomware ecosystem. DoppelPaymer intrusions have been linked to multiple initial access and access-broker pathways. Reported access vectors and precursor activity include QAKBOT-enabled compromises, SocGholish-delivered footholds, exploitation of exposed remote services and VPN infrastructure, and infections involving Emotet and Dridex that were later used to provide network access. Once inside a victim environment, operators have been observed or assessed using credential theft, administrative credentials, Cobalt Strike, PowerShell Empire, PsExec, BITS jobs, Group Policy deployment, scheduled tasks, and service-based execution to move laterally and prepare enterprise-wide ransomware deployment. Operational reporting describes DoppelPaymer as a human-operated ransomware threat that seeks privileged access in Windows domains before detonation. Observed behaviors include changing local user passwords, copying or replacing legitimate services to establish persistence, modifying boot configuration to ensure execution after reboot, rebooting systems, and then encrypting files at scale. The group has also been associated with targeting backup infrastructure, including attempts to access backup-management platforms, delete backups, and abuse cloud or administrative credentials to undermine recovery. In some cases, operators publicly exposed backup-administration credentials to pressure non-paying victims. Victimology shows repeated targeting of organizations in Mexico, Germany, the United States, France, Belgium, Japan, Taiwan, and the United Kingdom. Reported victims and sectors include state-owned energy, hospitals and healthcare providers, electronics and manufacturing firms, construction and automotive-related companies, universities, and local government or public-sector entities. High-profile incidents attributed to DoppelPaymer include attacks affecting Pemex, Uniklinik Düsseldorf, Compal Electronics, and Foxconn facilities in Mexico. DoppelPaymer has also been discussed in relation to broader criminal ecosystems around BitPaymer, Evil Corp-linked activity, and later offshoots such as Grief, though the exact organizational relationships are not always definitive. The dominant, high-confidence characterization is that DoppelPaymer is a Russia-linked cybercriminal ransomware and extortion operation focused on financially motivated attacks against enterprise victims.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
25 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as one of several ransomware groups that used SocGholish infections as an entry point for follow-on attacks.
Previously involved in ransomware attacks targeting Foxconn.
Conducted a ransomware attack against a Foxconn plant in Ciudad Juárez and demanded a $34 million ransom.
Ransomware operation that claimed a prior attack on Foxconn's CTBG MX facility, demanding a $34 million ransom after alleged data theft, large-scale server encryption, and backup destruction.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.