DoppelPaymer is a Windows ransomware family that emerged in 2019 as a fork of BitPaymer and operated under a ransomware-as-a-service model. It targets enterprise networks, organizations, and critical infrastructure, with victims spanning healthcare, energy, manufacturing, construction, and other industries worldwide. It encrypts files using AES-256 and RSA-2048 and creates separate ransom-information files for encrypted files. The malware embeds Process Hacker components to terminate security-related processes and uses packing and encrypted strings to hinder detection and analysis.
DoppelPaymer campaigns combine network-wide encryption with data theft and threats of public disclosure. Its operators launched a public leak site in early 2020 to publish stolen information and pressure non-paying victims. Distribution has included phishing and spam emails containing malicious JavaScript or VBScript attachments, and Emotet infections have enabled attacks. Operators have abused Cobalt Strike and PsExec for lateral movement and ransomware deployment, and Mimikatz for credential theft. Compromised backup-administration credentials have also been used as extortion leverage. The operation transitioned to Grief, also known as Pay or Grief, in 2021, retaining closely related ransomware code, encryption algorithms, and victim-negotiation infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Dabei handelte es sich um eine Lücke in der Citrix-VPN-Software, die unter dem Namen "Shitrix" bekannt wurde (CVE-2019-19781) ... Das wahrscheinlichste Szenario ist somit derzeit, dass die Cyberkriminellen die Shitrix-Lücke sehr bald nach ihrem Bekanntwerden und noch vor der Bereitstellung des Patches durch Citrix ausgenutzt haben. | So hätten die Angreifer eine Schadsoftware namens "DoppelPaymer" in das System geschleust. Dieser Verschlüsselungstrojaner sei bereits in zahlreichen anderen Fällen weltweit gegen Unternehmen und Institutionen ... eingesetzt worden.
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
These suspicions grow stronger with today’s report from Sophos, which notes that the same packer code was detected on Sophos-protected systems targeted with DoppelPaymer ransomware.
CYFIRMA Researchers suspect this threat actor to be responsible for operating DoppelPaymer and DoppelDridex.
Cybersecurity researchers, including TRU, believe the Grief Group is merely a rebrand of the DoppelPaymer Ransomware Group.
Cybersecurity researchers, including TRU, believe the Grief Group is merely a rebrand of the DoppelPaymer Ransomware Group.
The most active ransomware gang targeting Japanese entities appears to be the DoppelPaymer gang. The DoppelPaymer ransomware emerged in 2019 and is believed to have links with former members of the TA505 hacking group.
Doppel Spider opérerait lui une version modifiée de Dridex, DoppelDridex, ainsi qu’une variante du rançongiciel BitPaymer, DoppelPaymer.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
DoppelPaymer is an enterprise-targeting ransomware that compromises a corporate network, eventually gains access to admin credentials, and then deploys the ransomware on the network to encrypt all devices.
Erst jetzt, viele Monate später, haben sie diese Backdoor benutzt, um wieder Zugriff auf das Netz der Uni-Klinik zu erlangen.
Das wahrscheinlichste Szenario ist somit derzeit, dass die Cyberkriminellen die Shitrix-Lücke sehr bald nach ihrem Bekanntwerden und noch vor der Bereitstellung des Patches durch Citrix ausgenutzt haben. Sie sind dann darüber in das Netz der Uni-Klinik eingedrungen
DoppelPaymer uses a fairly sophisticated routine, starting off with network infiltration via malicious spam emails containing spear-phishing links or attachments designed to lure unsuspecting users into executing malicious code that is usually disguised as a genuine document.
DoppelPaymer uses a fairly sophisticated routine, starting off with network infiltration via malicious spam emails containing spear-phishing links or attachments designed to lure unsuspecting users into executing malicious code that is usually disguised as a genuine document.
DoppelPaymer is an enterprise-targeting ransomware that compromises a corporate network, eventually gains access to admin credentials, and then deploys the ransomware on the network to encrypt all devices.
Erst jetzt, viele Monate später, haben sie diese Backdoor benutzt, um wieder Zugriff auf das Netz der Uni-Klinik zu erlangen.
In early 2020, the following delivery mechanisms were seen – Group Policies ... – PsExec – BITS Jobs – Scheduled Tasks
The ransomware copies a legitimate service and replaces the original with a copy of itself
DoppelPaymer is an enterprise-targeting ransomware that compromises a corporate network, eventually gains access to admin credentials, and then deploys the ransomware on the network to encrypt all devices.
The ransomware copies a legitimate service and replaces the original with a copy of itself
such as the love of hiding RC4 encrypted strings using a 40 byte key that is reversed which is also used by Dridex and DoppelPaymer
With attackers leveraging the features that enable a user to execute processes on remote systems, PsExec can be abused for arbitrary command shell execution and lateral movement.
before encrypting devices on the network the attackers will first delete the backups so that they cannot be used to restore encrypted files.
“bestanden versleutelen” en “Single extortion: bestanden of systemen van het slachtoffer zijn versleuteld.”
DoppelPaymer has a crc32 list of processes and services it will terminate. If a process or service in its list is running, it will trigger the Process Hacker to terminate it.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
85 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only in related articles, not part of the main incident discussed.
Mentioned for comparison as a prominent ransomware family using similar extortion tactics.
Ransomware family previously distributed via SocGholish.
Named ransomware family deployed via SocGholish.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.