Skip to content

DoppelPaymer

DoppelPaymer is Windows-targeting enterprise ransomware, generally characterized as a 2019 fork of BitPaymer that operated through a ransomware-as-a-service model.

Profile source: Mallory opens in a new tab

DoppelPaymer

Family profile

DoppelPaymer is Windows-targeting enterprise ransomware, generally characterized as a 2019 fork of BitPaymer that operated through a ransomware-as-a-service model. It encrypts data across compromised corporate environments and has been used in high-impact attacks against organizations in sectors including manufacturing, construction, automotive, healthcare, government, energy, and logistics. The malware is associated with double-extortion operations: operators steal confidential information before or alongside encryption, then threaten publication through a public leak site to coerce payment. DoppelPaymer operators have also targeted backup infrastructure, including by obtaining privileged access and deleting or accessing backups before ransomware deployment.

Observed DoppelPaymer intrusions have involved credential dumping with Mimikatz and lateral movement or broad ransomware deployment using PsExec, Cobalt Strike, and PowerShell Empire. An intrusion at a German hospital was linked to exploitation of CVE-2019-19781, followed by deployment of a loader and a dormant backdoor before encryption. DoppelPaymer has been linked in reporting to the DoppelSpider activity cluster, though public attribution remains less certain than its technical lineage. Activity declined in 2021 as operators transitioned to Grief, also known as Pay or Grief; the two ransomware variants share closely related code, encryption design, victim portal functionality, and leak-site infrastructure.

Capabilities

  • Credential Theft
  • Exfiltration
  • Extortion
  • Lateral Movement

Operational record

1
YARA rules
4
Ransom notes
1
Leak sites
0 available

Reported operators

Threat actors

8 named in public reporting
DoppelSpider

CYFIRMA Researchers suspect this threat actor to be responsible for operating DoppelPaymer and DoppelDridex.

DoppelPaymer Ransomware Group

Cybersecurity researchers, including TRU, believe the Grief Group is merely a rebrand of the DoppelPaymer Ransomware Group.

Grief Ransomware Gang

Cybersecurity researchers, including TRU, believe the Grief Group is merely a rebrand of the DoppelPaymer Ransomware Group.

INDRIK SPIDER

Dridex and their operators, also known as “Evil Corp,” continues to successful experimenting with targeted highly-impactful bank fraud and ransomware operations including working with such targeted ransomware variants as “BitPaymer” and “DoppelPaymer”.

TA505

The most active ransomware gang targeting Japanese entities appears to be the DoppelPaymer gang. The DoppelPaymer ransomware emerged in 2019 and is believed to have links with former members of the TA505 hacking group.

DOPPEL SPIDER

Doppel Spider opérerait lui une version modifiée de Dridex, DoppelDridex, ainsi qu’une variante du rançongiciel BitPaymer, DoppelPaymer.

DoppelPaymer

The company’s Mexico operations were previously hit with a ransomware attack in 2020 by the DoppelPaymer gang, which demanded a $34 million ransom... The group stole about 100 GB of files.

Lockean

Lockean activity was first noticed in 2020 when the actor hit a French company in the manufacturing sector and deployed DoppelPaymer ransomware on the network.

Exploited software

Vulnerabilities linked to DoppelPaymer

1 CVEs

MITRE ATT&CK

DoppelPaymer in ATT&CK

47 distinct techniques

Reporting

Research mentioning DoppelPaymer

Jul 17
Sentinelone Labs

Maze Ransomware Update: Extorting and Exposing Victims - SentinelLabs

Maze emerged as one of the most influential ransomware operations targeting businesses, corporations, and municipal organizations, combining file encryption with data theft and public leak threats to force victims into paying. The group first spread through exploit kits and malicious spam, then shifted to more targeted intrusions using spear-phishing, exploitation of internet-facing services such as Citrix ADC/NetScaler and Pulse Secure VPN, and attacks against weak RDP credentials. Researchers described Maze as a C/C++ Windows PE malware with obfuscation, anti-analysis features, and a layered encryption scheme that paired ChaCha with RSA-2048. The operation also expanded its influence by forming a ransomware cartel with LockBit and RagnarLocker, sharing leak infrastructure and tradecraft in a model that helped normalize double-extortion tactics across the broader ransomware ecosystem.

Jan 1
Sophos Threat Research

Sophos MTR in Real Time: What is Astro Locker Team? | SOPHOS

Mount Locker emerged as a corporate-targeting ransomware operation that stole data before encrypting files and then demanded multi-million dollar payments while threatening to leak stolen information on a Tor-hosted extortion site. Reporting on early victims said the group had already listed multiple organizations on its leak portal and published at least one victim’s files after nonpayment. The malware used ChaCha20 for file encryption and an embedded RSA-2048 public key to protect encryption material, dropped a ransom note named RecoveryManual.html, and appended a .ReadManual.ID-style extension to encrypted files. Reverse-engineering of Mount Locker samples and later variants showed the ransomware also included operational features for enterprise-wide impact, including command-line options for targeting hosts, suppressing logs, avoiding process termination controls, and encrypting network resources. Analysts reported that newer builds added worm-like lateral movement by enumerating domain or network systems, requiring /LOGIN= and /PASSWORD= parameters for propagation, copying itself to remote machines, creating services named in an Update{GetTickCount()} pattern, and in some cases launching remotely through WMI under ROOT\CIMV2. The malware was also described as killing selected services and processes before encryption to maximize disruption.

Aug 4
Kienmanowar

[QuickNote] MountLocker - Some pseudo-code snippets | 0day in {REA_TEAM}

Jun 20
Github Web

Malware-Analysis-Reports/MountLocker at master · Finch4/Malware-Analysis-Reports · GitHub

May 23
Chuongdong

MountLocker Ransomware | Chuong Dong

May 13
Securelist

Evolution of JSWorm ransomware | Securelist

Nefilim emerged as a distinct ransomware operation built from Nemty 2.5 code, abandoning the earlier ransomware-as-a-service model in favor of private, targeted intrusions and email-based ransom negotiations. The malware encrypts files with AES-128 and protects keys with RSA-2048, appends the .NEFILIM extension, and drops NEFILIM-DECRYPT.txt, while also stealing data and threatening to publish it if victims do not pay. Researchers linked Nefilim to the broader JSWorm/Nemty/Nefilim lineage through shared cryptographic logic, ransom-note patterns, and infrastructure, showing a progression from mass distribution via the RIG exploit kit, spam, and the Trik/Phorpiex botnet to enterprise-focused attacks.

May 13
Securelist

Life of Maze ransomware | Securelist

May 12
Qualys

Nefilim Ransomware: Tactics, Impact, and Mitigation Strategies | Qualys

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.