DoppelDridex
- First seen
- 2019-04-01 00:00:00
- Malware type
- credential-stealer, trojan
- Family
- Malware family
- Last IoC activity
- 2026-06-27 11:35:56
- Profile updated
- 2026-07-07 12:40:36
Targeted industries: financial-services government-and-public-sector healthcare-and-pharmaceutical
Targeted regions: country_code:us country_code:gb country_code:de
Context
DoppelDridex is a fork of Indrik Spider's Dridex malware. DoppelDridex has been run as a parallel operation to Dridex with a different malware versioning system, different RSA key, and with different infrastructure.
Detection coverage
- 2 YARA rules
Detection rules
- SEKOIA_Loader_Win_Doppeldridex (yara-rule)
- MALPEDIA_Win_Doppeldridex_Auto (yara-rule)
Reports & references
- CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
- CISA — Aa22 110A (report)
- proofpoint.com — Ta575 Uses Squid Game Lures Distribute Dridex Malware (report)
- CrowdStrike — Doppelpaymer Ransomware And Dridex 2 (report)
- medium.com — Operation Synctrek E5013Df8D167 (report)
- redcanary.com — Grief Ransomware (report)
- twitter.com — 1453557686830727177 (report)
- CISA — Aa22 110A Joint Csa Russian State Sponsored And Criminal Cyber Threats To Critical Infrastructure 4 20 22 Final (report)
- blogs.blackberry.com — Zebra2104 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Doppeldridex (report)
- team-cymru.com — Webinject Panel Administration A Vantage Point Into Multiple Threat Actor Campaigns (report)
- security-soup.net — Doppeldridex Delivered Via Slack And Discord (report)
- fortinet.com — New Dridex Variant Being Spread By Crafted Excel Document (report)
- cyber-anubis.github.io — Dridex (report)
- 0ffset.net — Dridex Veh Api Obfuscation (report)
- bleepingcomputer.com — Log4J Vulnerability Now Used To Install Dridex Banking Malware (report)
- inquest.net — Dont Bring Dridex Home Holidays (report)