Netskope Threat Labs

DoppelPaymer

ATP Sandbox Adv. HeuristicsAVNetskope IPS

DoppelPaymer is a ransomware operation known for big game hunting against large organizations in healthcare, education, government, and critical manufacturing. Its operators exfiltrate data before encryption and run a leak site that publishes stolen material from victims who refuse to pay. The family shares its roots and tactics with the Evil Corp criminal network, and it faded from view after 2021 as its members moved between successor brands.

First seen
May 2022
Last seen
September 2026
Alert Name
ByteCode-MSIL.Trojan.DoppelPaymer
Gen:Variant.Ransom.DoppelPaymer.10
Gen:Variant.Ransom.DoppelPaymer.5
Gen:Variant.Ransom.DoppelPaymer.7
Win32.Ransomware.DoppelPaymer