Threat Actor Profile

Doppel Spider

Doppel Spider, also known as GOLD HERON, is a Russian-based cybercriminal group active since at least April 2019. They are infamous for operating ransomware families like DoppelPaymer and DoppelDridex, targeting organizations globally with sophisticated tactics.

Threat Actor Profile

Doppel Spider

Fancy Bear TTPs

Aenean interdum tempor lectus, nec rutrum nisl interdum ut. Aliquam mattis felis vulputate dui ultrices, ac finibus ligula interdum. Proin metus enim, sagittis fringilla viverra quis, pulvinar sit amet quam. Donec eget ullamcorper nibh. Praesent a nisl eu nunc interdum efficitur.

Country of Origin

Doppel Spider is believed to originate from the Russian Federation, as indicated by their operational patterns and affiliations.

Members

The exact number of members is unclear, but the group is suspected to be a splinter faction of INDRIK SPIDER, indicating a well-coordinated team with advanced capabilities.

Leadership

The leadership of Doppel Spider remains unknown. However, their operations suggest a highly organized and skilled team.

Tactics

Doppel Spider primarily focuses on financial gain through ransomware attacks, targeting high-value organizations.

Techniques

They employ phishing campaigns, malware distribution, and network reconnaissance to infiltrate and exploit systems.

Procedures

Their methods include deploying ransomware like DoppelPaymer and DoppelDridex, leveraging stolen credentials, and conducting data exfiltration.

Want to shut down threats before they start?

Indicators of Compromise (IOCs)

Organizations should monitor for:

  • Known Fancy Bear malware signatures (e.g., XAgent, ADVSTORESHELL).
  • Suspicious domains mimicking government or defense entities.
  • Zero-day exploits in applications like Microsoft Windows and Adobe Flash.
  • Abnormal network traffic patterns indicating command-and-control communications.

Key Victims

Fancy Bear targets include:

  • Governments (United States, Germany, France, Ukraine, and others).
  • Military Organizations (focus on NATO-aligned entities).
  • Media Outlets and Journalists (especially those covering Kremlin-related topics).
  • Critical Infrastructure (energy, aerospace, and defense).
  • International Sporting Organizations (e.g., WADA).
  • Political Groups (e.g., the Democratic National Committee).

Notable Cyber Attacks

Aenean interdum tempor lectus, nec rutrum nisl interdum ut. Aliquam mattis felis vulputate dui ultrices, ac finibus ligula interdum. Proin metus enim, sagittis fringilla viverra quis, pulvinar sit amet quam. Donec eget ullamcorper nibh. Praesent a nisl eu nunc interdum efficitur.

Notable Cyberattacks

One of their most significant operations involved a ransomware attack demanding 250 BTC, showcasing their ability to conduct high-stakes cybercrime.

Glitch effectGlitch effect

How to Defend Against Doppel Spider

1

Implement robust email filtering to block phishing attempts.

2

Regularly update and patch systems.

Huntress solutions help protect organizations by monitoring endpoints, detecting intrusions, and mitigating Doppel Spider threats withenterprise-grade technology.

Law Enforcement & Arrests

Law enforcement agencies, including Europol, have targeted Doppel Spider members, disrupting some of their operations.

References

Related Threat Actor Profiles

Notable developments include the U.S. indictment of GRU-affiliated officers in 2018. Despite these measures, Fancy Bear remains operational, emphasizing the challenges of deterring state-sponsored cyber actors.

Detect, Respond, Protect

See how the global Huntress SOC can augment your team
with 24/7 coverage and unmatched human expertise.
Start your free trial today.

Try Huntress for Free