DOPPEL SPIDER

Aliases: GOLD HERON

First seen
2019-06-01 00:00:00
Primary motivation
financial-gain
Sophistication
advanced
Resource level
organization
Actor type
criminal
Profile updated
2026-07-07 11:49:22

Targeted industries: financial-services healthcare-and-pharmaceutical government-and-public-sector manufacturing technology-and-telecommunications

Context

In June 2019, CrowdStrike Intelligence observed a source code fork of BitPaymer and began tracking the new ransomware strain as DoppelPaymer. Further technical analysis revealed an increasing divergence between two versions of Dridex, with the new version dubbed DoppelDridex. Based on this evidence, CrowdStrike Intelligence assessed with high confidence that a new group split off from INDRIK SPIDER to form the adversary DOPPEL SPIDER. Following DOPPEL SPIDER’s inception, CrowdStrike Intelligence observed multiple BGH incidents attributed to the group, with the largest known ransomware demand being 250 BTC. Other demands were not nearly as high, suggesting that the group conducts network reconnaissance to determine the value of the victim organization.

Reports & references

  • CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
  • secureworks.com — Gold Heron (report)

External references