Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors doppelpaymer

Description

Doppelpaymer is a ransomware family that encrypts user data and later on it asks for a ransom in order to restore original files. It is recognizable by its trademark file extension added to encrypted files: .doppeled. It also creates a note file named: ".how2decrypt.txt". Known victims: 25 4 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Doppelpaymer is a ransomware group active from 2019 to 2021, targeting victims with financial extortion through data encryption. Known for adding the '.doppeled' file extension and a decryption note, they employ tactics typical of ransomware operations but specific operational details are limited.

Goals & Targeting

Doppelpaymer's objectives align with typical ransomware groups—financial extortion through encryption. They appear to target a broad range of industries without sector-specific focus, indicating a general opportunistic approach toward victims.

Enhanced Description

Doppelpaymer ransomware encrypts user files, appending the .doppeled extension, and demands ransoms for decryption keys. A telltale sign is the '.how2decrypt.txt' file left behind. While they primarily seek financial gain, specific details on their attack vectors and targets remain sparse. Their longevity suggests moderate operational success but lack detailed campaign information.

Key Capabilities

  • File encryption with .doppeled extension
  • Creating '.how2decrypt.txt' ransom note
  • Potential lateral movement within networks
  • Possibly employing persistence mechanisms

MITRE ATT&CK Tactics

Initial Access
Execution
Impact

Software / Tooling

Cobalt Strike
Mimikatz

Campaigns & Victims

While specific campaigns aren't detailed, they show steady activity over two years. General targeting suggests a focus on any accessible victims without sector preference.

IOC Patterns

  • File extension '.doppeled'
  • Presence of '.how2decrypt.txt'
  • Network traffic post-encryption
  • Phishing emails with malicious attachments

Recommended Actions

  • Implement robust backup solutions for data recovery
  • Deploy endpoint detection and response tools
  • Monitor network activity for exfiltration attempts
  • Educate users to recognize phishing attempts

Suggested Tags

Ransomware
Financial Gain

Confidence Assessment

Moderate; primary info stems from file naming conventions. Gaps include specific TTPs and linked campaigns, limiting detailed insights.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Financial Gain

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
May 25, 2019
Last Seen
Apr 10, 2021
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.