DoppelPaymer, also known as the DoppelPaymer Gang or DoppelPaymer Group, is a financially motivated cybercriminal operation that emerged in 2019 using ransomware derived from BitPaymer. It conducts human-operated, targeted enterprise intrusions and has operated under a ransomware-as-a-service model. Its victims include manufacturers, aerospace suppliers, automotive companies, technology companies, energy enterprises, telecommunications providers, hospitals, universities and local governments across multiple regions. Notable victims include Pemex in Mexico, Compal Electronics in Taiwan and University Hospital Düsseldorf in Germany. The group uses double extortion, combining file encryption with theft of sensitive information and threats to publish it. It launched a public leak site in early 2020 and has demanded multimillion-dollar ransoms. Its targeting extends to backup infrastructure: operators have obtained backup and cloud credentials and publicly disclosed a non-paying victim’s Veeam administrator credentials to demonstrate access. DoppelPaymer intrusions have been enabled by phishing and malicious email attachments, Emotet infections and partnerships involving QakBot-compromised networks. Operators use valid administrative credentials to spread through Windows environments and deploy ransomware through Group Policy, PsExec, BITS jobs and scheduled tasks. Observed ransomware variants change local account passwords, establish service-based persistence, modify boot configuration to disable recovery and enable Safe Mode, reboot systems and encrypt files. The operation also terminates security-related processes to undermine endpoint defenses. In February 2023, German and Ukrainian authorities conducted coordinated searches targeting suspected core members, supported by Europol, Dutch police and the FBI. German authorities identified 37 corporate victims, while victims in the United States paid at least €40 million between May 2019 and March 2021.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
26 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as one of several ransomware groups that used SocGholish infections as an entry point for follow-on attacks.
Previously involved in ransomware attacks targeting Foxconn.
Conducted a ransomware attack against a Foxconn plant in Ciudad Juárez and demanded a $34 million ransom.
Ransomware operation that claimed a prior attack on Foxconn's CTBG MX facility, demanding a $34 million ransom after alleged data theft, large-scale server encryption, and backup destruction.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.