DoppelPaymer

Malware

⚠️ Overview

DoppelPaymer is a ransomware variant first observed in June 2019 by CrowdStrike, attributed to the financially motivated threat group Doppel Spider (also tracked as TA547). It belongs to the ransomware-as-a-service category and is known for employing a double-extortion model, encrypting files while exfiltrating sensitive data to pressure victims into payment.

🔧 Technical Capabilities

DoppelPaymer propagates via lateral movement using PowerShell and PsExec (MITRE ATT&CK T1021.002), leveraging compromised credentials or exploiting remote services. Initial access often exploits unpatched vulnerabilities such as CVE-2019-19781 in Citrix ADC or CVE-2020-1472 (ZeroLogon) for privilege escalation. The ransomware uses a custom encryption scheme combining Salsa20 for file encryption and RSA-4096 for key protection, with files renamed to append extensions like ".doppel" or ".paymer". Persistence is achieved through scheduled tasks or service installation (T1547.001), and evasion includes disabling Windows Defender and shadow copies via vssadmin. C2 communication is conducted over HTTPS or Tor to exfiltrate stolen data before encryption, using tools like WinSCP or RClone for upload (T1048).

📜 History & Notable Incidents

DoppelPaymer first appeared in June 2019, with a high-profile attack on the University Medical Center of Southern Nevada in July 2020, disrupting healthcare operations and leaking patient data. In October 2020, the ransomware hit Texas Department of Transportation, affecting internal systems. The group was known for publishing victim data on a leak site, and in 2022, law enforcement takedowns of affiliated infrastructure reduced activity (BleepingComputer).

🔍 Detection Indicators

Behavioral indicators include rapid file‑extension changes to ".doppel" or ".paymer", creation of the ransom note "How To Decrypt Files.txt", and execution of certutil for base64‑encoded downloads. Network IOCs include IP addresses associated with Tor exit nodes and known C2 domains. Specific file hashes reported by SentinelOne (SHA256: e.g., 1a2b3c...) vary per campaign, but mutex names like "DoppelPaymerMutex" have been observed.

☠️ Risk & Impact

DoppelPaymer encrypts critical files and exfiltrates sensitive data, causing operational downtime and reputational damage. Financial losses in affected organizations have exceeded millions of dollars, with ransom demands ranging from hundreds of thousands to millions. The healthcare, government, and education sectors are disproportionately targeted due to high‑impact systems and sensitive data (CISA advisory).

🛡️ Mitigation

Defensive measures include applying patches for CVE-2019-19781 and CVE-2020-1472, enforcing least‑privilege policies, and enabling multi‑factor authentication for remote access. Endpoint detection rules (e.g., Sigma rules for PsExec and certutil usage) and regular offline backups are critical, as recommended by MITRE ATT&CK detection controls D3-FEND.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.