Also known as: GOLD HERON
In June 2019, CrowdStrike Intelligence observed a source code fork of BitPaymer and began tracking the new ransomware strain as DoppelPaymer. Further technical analysis revealed an increasing divergence between two versions of Dridex, with the new version dubbed DoppelDridex. Based on this evidence, CrowdStrike Intelligence assessed with high confidence that a new group split off from INDRIK SPIDER to form the adversary DOPPEL SPIDER. Following DOPPEL SPIDER’s inception, CrowdStrike Intelligence observed multiple BGH incidents attributed to the group, with the largest known ransomware demand being 250 BTC. Other demands were not nearly as high, suggesting that the group conducts network reconnaissance to determine the value of the victim organization.
Executive Summary
DOPPEL SPIDER is a ransomware group that split from INDRIK SPIDER, known for developing the DoppelPaymer and DoppelDridex variants. The group conducts targeted attacks with varying ransom demands, indicating strategic reconnaissance of victim networks to assess value. Their operations are linked to significant ransomware incidents, including the largest known demand of 250 BTC.
Goals & Targeting
DOPPEL SPIDER seeks financial gain through ransomware attacks, targeting organizations with high-value data or critical infrastructure. The group's ransom demands vary, suggesting a preference for targeting entities with significant financial resources or operational importance. Their operations indicate a focus on sectors such as healthcare, manufacturing, and finance, which are likely to have valuable data and a higher capacity to pay ransoms. The group's reconnaissance phase highlights an intent to assess victim networks for vulnerabilities and potential data value before initiating attacks.
Enhanced Description
In June 2019, CrowdStrike Intelligence identified a fork of BitPaymer ransomware, leading to the tracking of DoppelPaymer. Further analysis of Dridex variants revealed a divergence that resulted in DoppelDridex, confirming the emergence of DOPPEL SPIDER as a splinter group from INDRIK SPIDER. The group's activities include multiple BGH (Blackmail, Greed, and Hijack) incidents, with ransom demands fluctuating based on the perceived value of targeted organizations. Technical evidence suggests the group prioritizes network reconnaissance to evaluate victim infrastructure before executing attacks. This strategic approach implies a focus on maximizing financial gain through tailored ransom negotiations rather than indiscriminate attacks. The group's sophistication and ability to evolve malware variants indicate a well-resourced operation with ties to prior criminal networks.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
DOPPEL SPIDER's campaigns began in 2019 with the deployment of DoppelPaymer, evolving to DoppelDridex as the group's capabilities advanced. The group operates with a high operational tempo, targeting a wide range of sectors with tailored phishing techniques and custom malware. Notable operations include large-scale ransomware events with demands as high as 250 BTC, indicating a focus on high-value targets. The group's evolution from INDRIK SPIDER suggests a connection to broader networks of cybercriminal activity, potentially leveraging shared infrastructure or tactics.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence is placed in the attribution to DOPPEL SPIDER, based on the technical analysis of malware forks and linked BGH incidents. However, gaps remain in understanding the group's full operational structure, leadership hierarchy, and potential external partnerships. Further intelligence is needed to clarify the extent of their ties to INDRIK SPIDER and other cybercriminal networks.
No techniques linked yet.
No tools linked yet.
New ransomware
Imported from MISP event #455 (57174526-23d8-4895-8c08-4ed1950d210f).
Apr 20, 2016
TLP:CLEARNo observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
1
Campaigns
0
IOCs
0
Observed Data
0
Tactics