DoppelPaymer is a Windows ransomware family that emerged in 2019 as a fork or offshoot of BitPaymer and became associated with enterprise-targeted, human-operated intrusions. It has been widely linked in public reporting to operators connected to the Dridex ecosystem and frequently discussed in connection with Evil Corp, although attribution is sometimes described as assessed or speculative rather than universally settled. The malware was used against large organizations and public institutions across sectors including energy, healthcare, manufacturing, construction, automotive, government, and education, with notable activity against high-value corporate networks and Japanese entities.
DoppelPaymer operations typically followed a targeted intrusion model rather than indiscriminate mass deployment. Reported intrusion chains include initial access via phishing-delivered malware such as Emotet and Dridex, exploitation of exposed remote services or enterprise vulnerabilities, and subsequent use of post-compromise tooling including Cobalt Strike, PowerShell Empire, PsExec, and Mimikatz. Operators were reported to move laterally, obtain privileged credentials, access domain resources and backup infrastructure, and then deploy ransomware broadly across reachable systems, often during nights or weekends to maximize disruption.
The malware encrypts files and is part of the broader double-extortion era of ransomware. Its operators publicly ran a leak site used to shame non-paying victims and publish stolen data, and they were reported to steal unencrypted files before or during ransomware deployment. Public extortion pressure also included exposing evidence of access to backup environments. Campaign reporting further indicates use of victim negotiation portals and live chat support. In 2021, activity under the DoppelPaymer name declined and the operation was widely assessed to have rebranded as Grief, which retained closely related code, portal logic, and extortion infrastructure.
DoppelPaymer has also been associated with operational behaviors beyond file encryption, including use of legitimate administrative tools for lateral movement and credential access, and at least one reported variant behavior that enumerated local users and changed passwords. The family is notable as one of the prominent enterprise ransomware strains that helped normalize data-theft-backed extortion and leak-site coercion in big-game hunting campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Dabei handelte es sich um eine Lücke in der Citrix-VPN-Software, die unter dem Namen "Shitrix" bekannt wurde (CVE-2019-19781) ... Das wahrscheinlichste Szenario ist somit derzeit, dass die Cyberkriminellen die Shitrix-Lücke sehr bald nach ihrem Bekanntwerden und noch vor der Bereitstellung des Patches durch Citrix ausgenutzt haben. | So hätten die Angreifer eine Schadsoftware namens "DoppelPaymer" in das System geschleust. Dieser Verschlüsselungstrojaner sei bereits in zahlreichen anderen Fällen weltweit gegen Unternehmen und Institutionen ... eingesetzt worden.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Dridex and their operators, also known as “Evil Corp,” continues to successful experimenting with targeted highly-impactful bank fraud and ransomware operations including working with such targeted ransomware variants as “BitPaymer” and “DoppelPaymer”.
The most active ransomware gang targeting Japanese entities appears to be the DoppelPaymer gang. The DoppelPaymer ransomware emerged in 2019 and is believed to have links with former members of the TA505 hacking group.
Doppel Spider opérerait lui une version modifiée de Dridex, DoppelDridex, ainsi qu’une variante du rançongiciel BitPaymer, DoppelPaymer.
The company’s Mexico operations were previously hit with a ransomware attack in 2020 by the DoppelPaymer gang, which demanded a $34 million ransom... The group stole about 100 GB of files.
Lockean activity was first noticed in 2020 when the actor hit a French company in the manufacturing sector and deployed DoppelPaymer ransomware on the network.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
DoppelPaymer is an enterprise-targeting ransomware that compromises a corporate network, eventually gains access to admin credentials, and then deploys the ransomware on the network to encrypt all devices.
Erst jetzt, viele Monate später, haben sie diese Backdoor benutzt, um wieder Zugriff auf das Netz der Uni-Klinik zu erlangen.
Das wahrscheinlichste Szenario ist somit derzeit, dass die Cyberkriminellen die Shitrix-Lücke sehr bald nach ihrem Bekanntwerden und noch vor der Bereitstellung des Patches durch Citrix ausgenutzt haben. Sie sind dann darüber in das Netz der Uni-Klinik eingedrungen
DoppelPaymer uses a fairly sophisticated routine, starting off with network infiltration via malicious spam emails containing spear-phishing links or attachments designed to lure unsuspecting users into executing malicious code that is usually disguised as a genuine document.
DoppelPaymer uses a fairly sophisticated routine, starting off with network infiltration via malicious spam emails containing spear-phishing links or attachments designed to lure unsuspecting users into executing malicious code that is usually disguised as a genuine document.
This would have eventually provided network access to the DoppelPayer actors who would then have used Cobalt Strike and PowerShell Empire to spread the ransomware laterally through the rest of the network.
DoppelPaymer is an enterprise-targeting ransomware that compromises a corporate network, eventually gains access to admin credentials, and then deploys the ransomware on the network to encrypt all devices.
Erst jetzt, viele Monate später, haben sie diese Backdoor benutzt, um wieder Zugriff auf das Netz der Uni-Klinik zu erlangen.
In early 2020, the following delivery mechanisms were seen – Group Policies ... – PsExec – BITS Jobs – Scheduled Tasks
The ransomware copies a legitimate service and replaces the original with a copy of itself
DoppelPaymer is an enterprise-targeting ransomware that compromises a corporate network, eventually gains access to admin credentials, and then deploys the ransomware on the network to encrypt all devices.
The ransomware copies a legitimate service and replaces the original with a copy of itself
such as the love of hiding RC4 encrypted strings using a 40 byte key that is reversed which is also used by Dridex and DoppelPaymer
DoppelPaymer is an enterprise-targeting ransomware that compromises a corporate network, eventually gains access to admin credentials, and then deploys the ransomware on the network to encrypt all devices.
With attackers leveraging the features that enable a user to execute processes on remote systems, PsExec can be abused for arbitrary command shell execution and lateral movement.
before encrypting devices on the network the attackers will first delete the backups so that they cannot be used to restore encrypted files.
Ransomware scrambles affected computer networks with encryption that can only be unlocked with keys provided once the victim has paid up. | A ransomware attack that hobbled a Georgia county government in early October reportedly disabled a database used to verify voter signatures in the authentication of absentee ballots.
DoppelPaymer has a crc32 list of processes and services it will terminate. If a process or service in its list is running, it will trigger the Process Hacker to terminate it.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
78 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only in related articles, not part of the main incident discussed.
Mentioned for comparison as a prominent ransomware family using similar extortion tactics.
Ransomware family previously distributed via SocGholish.
Named ransomware family deployed via SocGholish.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.