DOPPEL SPIDER is known for high-demand Big Game Hunting ransomware attacks.
Analyst brief
DOPPEL SPIDER (formerly GOLD HERON) is a threat actor that split from the INDRIK SPIDER group, formed after a source code fork of BitPaymer was observed. The group primarily conducts Big Game Hunting (BGH) ransomware attacks, with the largest known demand being 250 BTC, though other demands were lower, suggesting they engage in network reconnaissance. Their key tools include the DoppelPaymer ransomware and a diverged version of Dridex tracked as DoppelDridex. Defenders should focus on detecting network reconnaissance activities and monitor for TTPs associated with this group's ransomware family and its distinct Dridex variant.
DOPPEL SPIDER
GOLD HERON
unknown
In June 2019, CrowdStrike Intelligence observed a source code fork of BitPaymer and began tracking the new ransomware strain as DoppelPaymer. Further technical analysis revealed an increasing divergence between two versions of Dridex, with the new version dubbed DoppelDridex. Based on this evidence, CrowdStrike Intelligence assessed with high confidence that a new group split off from INDRIK SPIDER to form the adversary DOPPEL SPIDER. Following DOPPEL SPIDER’s inception, CrowdStrike Intelligence observed multiple BGH incidents attributed to the group, with the largest known ransomware demand being 250 BTC. Other demands were not nearly as high, suggesting that the group conducts network reconnaissance to determine the value of the victim organization.