DOPPEL SPIDER
Also reported as GOLD HERON, Doppel Spider, Gold Heron and Grief Group. Linked to Russia by one source.
Reports per quarter
Techniques seen in the last two years
- T1489 1 report
Counts come from technique IDs in the actor's report text.
CVEs named in reports
- CVE-2017-0199 KEV ransomware
- CVE-2018-13379 KEV ransomware
- CVE-2019-0604 KEV ransomware
- CVE-2019-11510 KEV ransomware
- CVE-2019-13720 KEV
- CVE-2019-18935 KEV ransomware
- CVE-2019-19781 KEV ransomware
- CVE-2020-0688 KEV ransomware
- CVE-2020-10189 KEV
- CVE-2020-1472 KEV ransomware
- CVE-2020-14882 KEV
- CVE-2020-2021 KEV ransomware
Show all 21 CVEs Show fewer
- CVE-2021-20016 KEV ransomware
- CVE-2021-21972 KEV ransomware
- CVE-2021-22205 KEV ransomware
- CVE-2021-26084 KEV ransomware
- CVE-2021-30116 KEV ransomware
- CVE-2021-40539 KEV ransomware
- CVE-2021-440077
- CVE-2021-44228 KEV ransomware
- CVE-2021-44515 KEV
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
Indrik Spider - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Indrik Spider - Threat Group Cards: A Threat Actor Encyclopedia
-
Smoky Spider - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Smoky Spider - Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor FlawedAmmyy (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Dridex (Malware Family)
-
TA505, Graceful Spider, Gold Evergreen
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor TA505, Graceful Spider, Gold Evergreen
-
Doppel Spider - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Doppel Spider - Threat Group Cards: A Threat Actor Encyclopedia
-
Schlag gegen international agierendes Netzwerk von Cyber-Kriminellen
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Schlag gegen international agierendes Netzwerk von Cyber-Kriminellen
Show all 72 reports Show fewer
-
The Ransomware Threat Landscape: What to Expect in 2022
The original link failed its last check. Original publisher Detailsfor The Ransomware Threat Landscape: What to Expect in 2022
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Report2022GTR
-
Threat Intelligence Report- The Evolution of Doppel Spider from BitPaymer to Grief Ransomware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Intelligence Report- The Evolution of Doppel Spider from BitPaymer to Grief Ransomware
-
The original link failed its last check. Original publisher Detailsfor GriefRansomware_Whitepaper
-
DoppelDridex Delivered via Slack and Discord
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor DoppelDridex Delivered via Slack and Discord
-
DoppelDridex Delivered via Slack and Discord
The original link failed its last check. Original publisher Detailsfor DoppelDridex Delivered via Slack and Discord
-
Big Game Hunting TTPs Continue to Shift After DarkSide Pipeline Attack
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Big Game Hunting TTPs Continue to Shift After DarkSide Pipeline Attack
-
Ransomware Actors Evolved Their Operations in 2020
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ransomware Actors Evolved Their Operations in 2020
-
The_CrowdStrike_2021_Global_Threat_Report
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The_CrowdStrike_2021_Global_Threat_Report
-
Zooming into Darknet Threats Targeting Japanese Organizations
The original link failed its last check. Original publisher Detailsfor Zooming into Darknet Threats Targeting Japanese Organizations
-
What's behind the increase in ransomware attacks this year?
The original link failed its last check. Original publisher Detailsfor What's behind the increase in ransomware attacks this year?
-
Double Trouble- Ransomware with Data Leak Extortion, Part 1
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Double Trouble- Ransomware with Data Leak Extortion, Part 1
-
Double Trouble- Ransomware with Data Leak Extortion, Part 1
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Double Trouble- Ransomware with Data Leak Extortion, Part 1
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor CERTFR-2020-CTI-008
-
Manufacturing Industry in the Adversaries’ Crosshairs
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Manufacturing Industry in the Adversaries’ Crosshairs
-
Report2020CrowdStrikeGlobalThreatReport
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Report2020CrowdStrikeGlobalThreatReport
Newest first. Details opens the report in Explore.