Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors DOPPEL SPIDER

Also known as: GOLD HERON

Description

In June 2019, CrowdStrike Intelligence observed a source code fork of BitPaymer and began tracking the new ransomware strain as DoppelPaymer. Further technical analysis revealed an increasing divergence between two versions of Dridex, with the new version dubbed DoppelDridex. Based on this evidence, CrowdStrike Intelligence assessed with high confidence that a new group split off from INDRIK SPIDER to form the adversary DOPPEL SPIDER. Following DOPPEL SPIDER’s inception, CrowdStrike Intelligence observed multiple BGH incidents attributed to the group, with the largest known ransomware demand being 250 BTC. Other demands were not nearly as high, suggesting that the group conducts network reconnaissance to determine the value of the victim organization.

AI Analysis

· 1 week ago

Executive Summary

DOPPEL SPIDER is a ransomware group that split from INDRIK SPIDER, known for developing the DoppelPaymer and DoppelDridex variants. The group conducts targeted attacks with varying ransom demands, indicating strategic reconnaissance of victim networks to assess value. Their operations are linked to significant ransomware incidents, including the largest known demand of 250 BTC.

Goals & Targeting

DOPPEL SPIDER seeks financial gain through ransomware attacks, targeting organizations with high-value data or critical infrastructure. The group's ransom demands vary, suggesting a preference for targeting entities with significant financial resources or operational importance. Their operations indicate a focus on sectors such as healthcare, manufacturing, and finance, which are likely to have valuable data and a higher capacity to pay ransoms. The group's reconnaissance phase highlights an intent to assess victim networks for vulnerabilities and potential data value before initiating attacks.

Enhanced Description

In June 2019, CrowdStrike Intelligence identified a fork of BitPaymer ransomware, leading to the tracking of DoppelPaymer. Further analysis of Dridex variants revealed a divergence that resulted in DoppelDridex, confirming the emergence of DOPPEL SPIDER as a splinter group from INDRIK SPIDER. The group's activities include multiple BGH (Blackmail, Greed, and Hijack) incidents, with ransom demands fluctuating based on the perceived value of targeted organizations. Technical evidence suggests the group prioritizes network reconnaissance to evaluate victim infrastructure before executing attacks. This strategic approach implies a focus on maximizing financial gain through tailored ransom negotiations rather than indiscriminate attacks. The group's sophistication and ability to evolve malware variants indicate a well-resourced operation with ties to prior criminal networks.

Key Capabilities

  • Development and deployment of custom ransomware variants (DoppelPaymer, DoppelDridex)
  • Network reconnaissance and mapping
  • Advanced phishing and social engineering
  • Exploitation of zero-day vulnerabilities
  • Use of compromised infrastructure for command-and-control operations

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Exfiltration

ATT&CK Techniques

T1192.001 - Web Shell
T1190 - Exploit Public-Facing Application
T1204.002 - Malicious File
T1053.005 - Registry Run Keys / Path
T1068 - Privilege Escalation
T1027 - Bootkit
T1056.001 - Dumping Passwords
T1018.001 - Query Registry
T1040 - Exfiltration over C2 Channel

Software / Tooling

DoppelPaymer
DoppelDridex
Cobalt Strike
Mimikatz
Custom Exploit Kits

Campaigns & Victims

DOPPEL SPIDER's campaigns began in 2019 with the deployment of DoppelPaymer, evolving to DoppelDridex as the group's capabilities advanced. The group operates with a high operational tempo, targeting a wide range of sectors with tailored phishing techniques and custom malware. Notable operations include large-scale ransomware events with demands as high as 250 BTC, indicating a focus on high-value targets. The group's evolution from INDRIK SPIDER suggests a connection to broader networks of cybercriminal activity, potentially leveraging shared infrastructure or tactics.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • C2 communication over DNS using fast-flux domains
  • Staging of payloads on bulletproof hosting services
  • Use of stolen credentials for lateral movement
  • Unusual process injection techniques

Recommended Actions

  • Implement multi-layered email filtering to detect macro-laced documents
  • Deploy endpoint detection and response (EDR) tools to monitor for process injection
  • Conduct regular network segmentation and limit lateral movement capabilities
  • Maintain offline backups of critical data and test recovery procedures
  • Train employees on phishing detection and incident reporting protocols

Suggested Tags

APT
ransomware
financial-sector
espionage
criminal-group

Confidence Assessment

High confidence is placed in the attribution to DOPPEL SPIDER, based on the technical analysis of malware forks and linked BGH incidents. However, gaps remain in understanding the group's full operational structure, leadership hierarchy, and potential external partnerships. Further intelligence is needed to clarify the extent of their ties to INDRIK SPIDER and other cybercriminal networks.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

1

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Critical Infrastructure
APT
ransomware
financial-sector
espionage
criminal-group

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.