Doppelpaymer

Malware updated 2 months ago (2024-10-02T22:00:54.642Z)
Download STIX
Preview STIX
DoppelPaymer is a type of malware, specifically ransomware, that was initially developed and operated by the GOLD DRAKE threat group under the name BitPaymer. The software was later reworked and renamed to DoppelPaymer by another threat group, GOLD HERON. This malicious software first appeared in mid-2019 and began being used for double extortion attacks in early 2020. It has primarily targeted large organizations, demanding ransoms exceeding $1 million. Notable victims include computer manufacturer ASUS, municipalities like Augusta, George, and energy giant ConocoPhillips. In 2021, the ransomware underwent another rebranding and started operating under the name Grief. Law enforcement agencies from Germany and Ukraine conducted operations targeting key members of the DoppelPaymer ransomware group in February 2023. Two individuals, including a German national and Turashev, who had been wanted by German law enforcement since 2023 for his alleged involvement in running the ransomware, were arrested. These arrests marked significant progress in the ongoing fight against cybercrime and ransomware threats. The arrest of the DoppelPaymer operators aligns with a broader trend of increased law enforcement activity against ransomware gangs. Earlier in the same year, agencies successfully disrupted the HIVE and Genesis ransomware operations. Additionally, the suspected developer of the Ragnar Locker ransomware gang was apprehended in Paris. Despite these successes, DoppelPaymer remains an active threat, underscoring the importance of continued vigilance and cybersecurity measures among potential target organizations.
Description last updated: 2024-10-02T21:16:21.320Z
What's your take? (Question 1 of 5)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
BitPaymer is a possible alias for Doppelpaymer. BitPaymer is a type of malware, specifically ransomware, that was operated by the cybercriminal group known as GOLD DRAKE. It is designed to infiltrate systems and encrypt data, holding it hostage until a ransom is paid. This malicious software became prominent in conjunction with the rise of Ransom
3
Grief is a possible alias for Doppelpaymer. Grief is a potent malware that evolved from the DoppelPaymer ransomware, first appearing in mid-2019 and used for double extortion attacks beginning in early 2020. The malware was rebranded as Grief in 2021 under the alleged direction of an individual named Turashev, who has been sought by German la
3
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Ransomware
Europol
Police
Malware
Extortion
Cybercrime
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Associated Malware
To see the evidence that has resulted in these malware associations, create a free account
Alias DescriptionAssociation TypeVotes
The Dridex Malware is associated with Doppelpaymer. Dridex is a notorious malware, specifically a banking Trojan, designed to exploit and damage computer systems, often infiltrating through suspicious downloads, emails, or websites. This malicious software was primarily used by the Russian cybercriminal group, Evil Corp, founded in 2014. The group taUnspecified
3
The Qbot Malware is associated with Doppelpaymer. Qbot, also known as Qakbot or Pinkslipbot, is a modular information stealer malware that first emerged in 2007 as a banking trojan. Its evolution has seen it become an advanced strain of malware used by multiple cybercriminal groups to prepare compromised networks for ransomware infestations. The fiUnspecified
2
The Emotet Malware is associated with Doppelpaymer. Emotet is a notorious malware, short for malicious software, that is designed to exploit and damage computers or devices. It can infiltrate systems through suspicious downloads, emails, or websites, often unbeknownst to the user, with the potential to steal personal information, disrupt operations, Unspecified
2
Source Document References
Information about the Doppelpaymer Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
BankInfoSecurity
2 months ago
CERT-EU
2 years ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
2 years ago
Naked Security
2 years ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
Malwarebytes
a year ago
CERT-EU
a year ago
CERT-EU
2 years ago
Securityaffairs
2 years ago