Doppelpaymer Ransomware

Description Summary

Doppelpaymer is a ransomware family that encrypts user data and later on it asks for a ransom in order to restore original files. It is recognizable by its trademark file extension added to encrypted files: .doppeled. It also creates a note file named: ".how2decrypt.txt".

Threat Actor

BitPaymer fork linked to Evil Corp/Indrik Spider offshoot; Europol/German arrests in 2023.

Technical Indicators

Encryption Extension
.doppeled
Encryption Algorithm
AES-256 + RSA-2048/4096
Ransom Note Name
.how2decrypt.txt
Targeted Industries
Government, Healthcare, Critical infrastructure
First Seen
June 2019
Last Seen
2022 (rebranded to Grief; arrests 2023)
Geographical Location
United States, Europe

MITRE ATT&CK Matrix

Tactic TTP Technique Name
Impact x 2 T1486 Data Encrypted for Impact
T1490 Inhibit System Recovery
Exfiltration x 1 T1567 Exfiltration Over Web Service (leak site)
Initial Access x 2 T1190 Exploit Public-Facing Application
T1078 Valid Accounts