Description Summary
Doppelpaymer is a ransomware family that encrypts user data and later on it asks for a ransom in order to restore original files. It is recognizable by its trademark file extension added to encrypted files: .doppeled. It also creates a note file named: ".how2decrypt.txt".
Threat Actor
BitPaymer fork linked to Evil Corp/Indrik Spider offshoot; Europol/German arrests in 2023.
Technical Indicators
Encryption Extension
.doppeled
Encryption Algorithm
AES-256 + RSA-2048/4096
Ransom Note Name
.how2decrypt.txt
Targeted Industries
Government, Healthcare, Critical infrastructure
First Seen
June 2019
Last Seen
2022 (rebranded to Grief; arrests 2023)
Geographical Location
United States, Europe
MITRE ATT&CK Matrix
| Tactic | TTP | Technique Name |
|---|---|---|
| Impact x 2 | T1486 | Data Encrypted for Impact |
| T1490 | Inhibit System Recovery | |
| Exfiltration x 1 | T1567 | Exfiltration Over Web Service (leak site) |
| Initial Access x 2 | T1190 | Exploit Public-Facing Application |
| T1078 | Valid Accounts |