Ransomware Group intelligence
Doppelpaymer
InactiveTrack Doppelpaymer with 25 published victims and 1 known leak locations in a single intelligence view.
Overview
Doppelpaymer is tracked by Breach House as a ransomware group with 25 published victims.
United States is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 1h ago | hpoo4dosa3x4ognfxpqcrjwnsigvslm7kv6hvmhh2yqczaxy3j6qnwad.onion |
Top Activity Sectors (10)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Doppelpaymer, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: doppelpaymer executes malicious payloads via PowerShell scripts to stage ransomware binaries and disable security tools.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: doppelpaymer leverages Registry Run Keys to persist execution of its loader process on system startup.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: doppelpaymer disables antivirus and monitoring tools by terminating processes and modifying Windows Defender configurations.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1027.002 Software Packing Stealth
What they do: doppelpaymer packs its malware binaries to evade static detection while maintaining executable functionality.
What that means: Adversaries may perform software packing or virtual machine software protection to conceal their code.
-
T1070.004 File Deletion Stealth
What they do: doppelpaymer deletes Volume Shadow Copies and backup files via vssadmin and native Windows commands to prevent recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1018 Remote System Discovery Discovery
What they do: doppelpaymer uses Remote System Discovery to identify additional hosts within the victim network for lateral movement.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1135 Network Share Discovery Discovery
What they do: doppelpaymer scans network shares using Windows tools to identify victim file structures for encryption targets.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: doppelpaymer moves laterally via SMB/Windows Admin Shares to access and encrypt files across networked systems.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: doppelpaymer encrypts victim files using strong symmetric encryption, targeting documents, images, and system directories.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: doppelpaymer calls system recovery inhibitors like shutdown scripts to prevent forensic analysis and system restoration.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Ransom Notes (4)
▼The note this group leaves on a compromised machine. Click a filename to read it.
doppelpaymer4.txt
Your network has been penetrated. All files on each host in the network have been encrypted with a strong algorythm. Backups were either encrypted or deleted or backup disks were formatted. Shadow copies also removed, so F8 or any other methods may damage encrypted data but not recover. We exclusively have decryption software for your situation No decryption software is available in the public. DO NOT RESET OR SHUTDOWN - files may be damaged. DO NOT RENAME OR MOVE the encrypted and readme files. DO NOT DELETE readme files. DO NOT use any recovery software with restoring files overwriting encrypted. This may lead to the impossibility of recovery of the certain files. To get info (decrypt your files) contact us at your personal page: 1. Download and install Tor Browser: https://www.torproject.org/download/ 2. After a successful installation, run the browser and wait for initialization. 3. Type in the address bar: http://q7wp5u55lhtuafjtsl6lkt24z4wvon2jexfzhzqqfrt3bqnpqboyqoid.onion/order/[snip] 4. Follow the instructions on the site 5. You should get in contact in 48 HOURS since your systems been infected. 6. The link above is valid for 7 days. After that period if you not get in contact your local data would be lost completely. 7. Questions? e-mail: [email protected] If email not working - new one you can find on a tor page. The faster you get in contact - the lower price you can expect. DATA [snip]
doppelpaymer3.txt
Your network has been hacked.
Your ID: 191
Your files, backups and shadow copies are unavailable until you pay for a decryption tool.
If no contact made in 3 business days after the infection
first portion of data will be shared to public at
http://hpoo4dosa3x4ognfxpqcrjwnsigvslm7kv6hvmhh2yqczaxy3j6qnwad.onion
and all the rest will remain unreachable to you.
TO SAVE YOUR DATA FROM DESTRUCTION:
DO NOT RESET OR SHUTDOWN your PC or server.
DO NOT RENAME/ MOVE/ DELETE the encrypted and readme files.
DO NOT USE ANY RECOVERY TOOLS that is aimed to restore encrypted files.
TO GET YOUR DATA BACK contact us on your personal page:
1. Download and install Tor Browser: https://www.torproject.org/download/
2. Run the browser and wait for initialization.
3. Copy to the address bar:
http://thw73ky2jphtcfrwoze5ddk3wbkc2t24r55guu3agwjchn3g6p755kyd.onion/order/[snip]
4. Follow the instructions on the site.
5. Contact us via email [email protected] OR live chat on your personal page.
7. The link above is valid for 21 days.
8. If you ask about proof of data exfiltrated before payment -
we will share proofs at our data leaks portal.
doppelpaymer1.txt
[snip]
Your network has been hacked.
Your ID: 106
Your files, backups and shadow copies are unavailable until you pay for a decryption tool.
Otherwise your sensitive data will be shared to public at
http://hpoo4dosa3x4ognfxpqcrjwnsigvslm7kv6hvmhh2yqczaxy3j6qnwad.onion
and all the rest will remain unreachable to you.
TO SAVE YOUR DATA FROM DESTRUCTION:
DO NOT RESET OR SHUTDOWN your PC or server.
DO NOT RENAME/ MOVE/ DELETE the encrypted and readme files.
DO NOT USE ANY RECOVERY TOOLS that is aimed to restore encrypted files.
TO GET YOUR DATA BACK contact us:
[email protected]
OR
[email protected]
Contact us within 48 HOURS from the date your network have been infected.
After the period expires and no contact is made, the link and keys for your data will be erased completely.
doppelpaymer2.txt
Your network was hacked. Your ID: 269 DO NOT RESET OR SHUTDOWN your PC or server. DO NOT RENAME/ MOVE/ DELETE the encrypted and readme files. Info: http://fcjam663uvgid2xbar24kab2vt4hjzsn6o77glh35jscuo567b2mnyqd.onion/order/[snip] [email protected] If you decide not to cooperate your sensitive data will be shared to public at http://hpoo4dosa3x4ognfxpqcrjwnsigvslm7kv6hvmhh2yqczaxy3j6qnwad.onion and all the rest will remain unreachable to you.
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (25)
Search, filter and paginate the victim timeline for Doppelpaymer. Showing 1–25 of 25.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Office of the Attorney General id603 View details | United States | Finance / Legal / Insurance | — | |
|
No additional victim description available. |
|||||
| Ransomware | Azusa police department id589 View details | United States | Public Sector | — | |
|
No additional victim description available. |
|||||
| Ransomware | Manutan id585 View details | France | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Kia Motors America (KMA) id583 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Cuyahoga Metropolitan Housing Authority id579 View details | United States | Construction / Real Estate | — | |
|
No additional victim description available. |
|||||
| Ransomware | Foxconn id530 View details | Mexico | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Delaware County id529 View details | United States | Finance / Legal / Insurance | — | |
|
No additional victim description available. |
|||||
| Ransomware | Compal id519 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Banijay Group SAS id515 View details | France | Services | — | |
|
No additional victim description available. |
|||||
| Ransomware | Chatham County Government id512 View details | United States | Public Sector | — | |
|
No additional victim description available. |
|||||
| Ransomware | Hall County id493 View details | United States | Public Sector | — | |
|
No additional victim description available. |
|||||
| Ransomware | Newcastle University id466 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | 4 Canadian courier divisions of TFI International's Canpar Express id462 View details | Canada | Communication / Marketing | — | |
|
No additional victim description available. |
|||||
| Ransomware | Boyce Technologies (device manufacturer- transit communication systems and now ventilators b/c of COVID-19) id451 View details | United States | IT | — | |
|
No additional victim description available. |
|||||
| Ransomware | Knoxville PD and City of Knoxville, TN (Knox County) id417 View details | United States | Public Sector | — | |
|
No additional victim description available. |
|||||
| Ransomware | City of Florence, Alabama id400 View details | United States | Public Sector | — | |
|
No additional victim description available. |
|||||
| Ransomware | Digital Management Inc. (NASA Contractor) id398 View details | United States | IT | — | |
|
No additional victim description available. |
|||||
| Ransomware | Mitsubishi id384 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Afpa id21582 View details | France | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Kimchuk id336 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | City of Torrance (Los Angeles County) id333 View details | United States | Public Sector | — | |
|
No additional victim description available. |
|||||
| Ransomware | Visser Precision id324 View details | United States | Communication / Marketing | — | |
|
No additional victim description available. |
|||||
| Ransomware | Bretagne Telecom id313 View details | France | Telecommunications | — | |
|
No additional victim description available. |
|||||
| Ransomware | Chilean Ministry of Agriculture id276 View details | Chile | Agriculture / Food | — | |
|
No additional victim description available. |
|||||
| Ransomware | City of Edcouch id275 View details | United States | Public Sector | — | |
|
No additional victim description available. |
|||||