DoppelDridex is a modified Dridex variant associated with the cybercriminal group Doppel Spider, a subgroup or closely related offshoot of Evil Corp that emerged around 2019 alongside the DoppelPaymer ransomware operation. It has been used in banking-fraud campaigns and as part of broader financially motivated intrusion chains that can culminate in ransomware deployment. Reporting places DoppelDridex within the wider Dridex ecosystem, which evolved from the Bugat and GameOverZeuS lineage and is characterized by modular functionality, resilient botnet operations, and close overlap with other major eCrime services and malware families.
High-confidence reporting indicates Doppel Spider began operating DoppelDridex from April 2019. The malware has been observed as a second-stage payload delivered by other criminal distribution services, particularly Emotet, and has also been referenced in access-broker and botnet ecosystems that facilitated delivery of follow-on malware for multiple threat actors. DoppelDridex activity is linked to the same criminal milieu that used Dridex for credential theft, reconnaissance, and follow-on deployment of ransomware, especially BitPaymer and later DoppelPaymer.
As a Dridex-derived banking trojan, DoppelDridex is associated with credential theft and post-compromise activity in support of financial fraud and downstream intrusion objectives. Its operator, Doppel Spider, has been assessed as collaborating with or remaining operationally tied to Evil Corp rather than being wholly separate. Victimology and targeting are consistent with broad financially motivated campaigns rather than a single vertical, with use in both banking-fraud operations and enterprise compromises that support extortion-oriented attacks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
depuis avril 2019,le groupe d’attaquants Doppel Spider opère une version modifiée de Dridex, Doppel-Dridex
2 distinct techniques documented for this family, organized by ATT&CK tactic.
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as a banking trojan that can be delivered by Emotet as a second-stage payload.
DoppelDridex is a modified variant of Dridex operated by the threat actor Doppel Spider, used for banking credential theft and as an initial access vector for ransomware deployment, particularly DoppelPaymer.
Malware referenced in the eCrime ecosystem relationship diagram (name suggests Dridex-related tooling used in Doppel SPIDER ecosystem).
Modified Dridex variant attributed to Doppel Spider, used in both banking fraud and ransomware intrusion chains.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.