Uptime Hamster: 11d 9h 24mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza DOPPEL SPIDER

DOPPEL SPIDER

0 incidentes 0 paises 0 sectores apt RU Ultimo: -
Aliases: GOLD HERON
Ver en IntelTracker → APTTrail →
DOPPEL SPIDER is a financially motivated cybercriminal group first observed in April 2019, primarily known for operating the DoppelPaymer ransomware and its successor, Grief. Assessed with high confidence to be of Russian origin, the group's core motivation is financial gain through targeted ransomware attacks against large organizations. While initially operating DoppelPaymer as a fork of the BitPaymer ransomware, they evolved their operations to include the Grief ransomware, aiming to evade sanctions and continue their high-value campaigns. A defining characteristic of DOPPEL SPIDER is its use of double extortion tactics, which involves not only encrypting a victim's data but also exfiltrating sensitive information and threatening its public release if the ransom is not paid. The group is also distinct for directly contacting victims, sometimes via telephone, to pressure them into paying the ransom. This group is sometimes referred to by the alias GOLD HERON and its ransomware operat

Aliases del actor

GOLD HERON

Actores similares

doppel-spideractor · 1Scattered Spideractor · 2Indrik Spideractor · 1salty-spideractor · 1brain-spideractor · 1skeleton-spideractor · 1bamboo-spideractor · 1andromeda-spideractor · 1cobalt-spideractor · 1boson-spideractor · 1

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / leak siteunknownduckduckgo.comDOPPEL SPIDER
DLS / leak siteunknownduckduckgo.comDOPPEL SPIDER
Motivacion