National Cyber Warfare Foundation (NCWF)

DOPPEL SPIDER


0 user ratings
2024-07-26 20:09:14
blscott

 - archive -- 
In June 2019, CrowdStrike Intelligence observed a source code fork of BitPaymer and began tracking the new ransomware strain as DoppelPaymer. Further technical analysis revealed an increasing divergence between two versions of Dridex, with the new version dubbed DoppelDridex. Based on this evidence, CrowdStrike Intelligence assessed with high confidence that a new group split off from INDRIK SPIDER to form the adversary DOPPEL SPIDER. Following DOPPEL SPIDERas inception, CrowdStrike Intelligence observed multiple BGH incidents attributed to the group, with the largest known ransomware demand being 250 BTC. Other demands were not nearly as high, suggesting that the group conducts network reconnaissance to determine the value of the victim organization.
Alternate Group Names
GOLD HERON, \\

Alternative Names
Gold HeronDoppelPaymerdoppel paymerDoppelPaymer groupDoppelPaymer ransomwareDoppelPaymer gang

---------------------------------------------

(CrowdStrike) CrowdStrike Intelligence has identified a new ransomware variant identifying itself as BitPaymer. This new variant was behind a series of ransomware campaigns beginning in June 2019, including attacks against the City of Edcouch, Texas and the Chilean Ministry of Agriculture. We have dubbed this new ransomware DoppelPaymer because it shares most of its code with the BitPaymer ransomware operated by \\\'Indrik Spider\\\'. However, there are a number of differences between DoppelPaymer and BitPaymer, which may signify that one or more members of Indrik Spider have split from the group and forked the source code of both Dridex and BitPaymer to start their own Big Game Hunting ransomware operation. DoppelPaymer has been observed to be distributed by Smoke Loader (operated by \\\'Smoky Spider\\\') and Emotet (operated by \\\'Mummy Spider, TA542\\\').\\

First Seen- 2019

Other Names: (other than above mentioned): Grief Group

Targets: Austria, Brazil, Canada, Chile, Dominican Republic, France, Germany, Greece, Italy, Mexico, Portugal, Spain, Switzerland, Thailand, United Kingdom, United States - 

Target Categories- Government, Manufacturing

Tools-

Cobalt
Strike (category: Tools)


type: Backdoor, Vulnerability scanner, Keylogger, Tunneling, Loader,
Exfiltration

Cobalt Strike is a paid penetration testing product that allows an attacker to
deploy an agent named \'Beacon\' on the victim machine. Beacon includes a wealth
of functionality to the attacker, including, but not limited to command
execution, key logging, file transfer, SOCKS proxying, privilege escalation,
mimikatz, port scanning and lateral movement. Beacon is in-memory/file-less, in
that it consists of stageless or multi-stage shellcode that once loaded by
exploiting a vulnerability or executing a shellcode loader, will reflectively
load itself into the memory of a process without touching the disk. It supports
C2 and staging over HTTP, HTTPS, DNS, SMB named pipes as well as forward and
reverse TCP; Beacons can be daisy-chained. Cobalt Strike comes with a toolkit
for developing shellcode loaders, called Artifact Kit. The Beacon implant has
become popular amongst targeted attackers and criminal users as it is well
written, stable, and highly customizable.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=7ea8d070-cfd7-473c-a615-437fc292af55

https://www.cobaltstrike.com/

https://www.fireeye.com/blog/threat-research/2017/06/phished-at-the-request-of-counsel.html

https://blogs.jpcert.or.jp/en/2018/08/volatility-plugin-for-detecting-cobalt-strike-beacon.html

https://github.com/JPCERTCC/aa-tools/blob/master/cobaltstrikescan.py

https://www.fireeye.com/blog/threat-research/2018/11/not-so-cozy-an-uncomfortable-examination-of-a-suspected-apt29-phishing-campaign.html

http://blog.morphisec.com/new-global-attack-on-point-of-sale-systems

https://www.lac.co.jp/lacwatch/people/20180521_001638.html

https://www.pentestpartners.com/security-blog/cobalt-strike-walkthrough-for-red-teamers/

https://www.bleepingcomputer.com/news/security/threat-actors-use-older-cobalt-strike-versions-to-blend-in/

https://documents.trendmicro.com/assets/white_papers/wp-cashing-in-on-atm-malware.pdf

https://blog.talosintelligence.com/2020/09/coverage-strikes-back-cobalt-strike-paper.html

https://www.bleepingcomputer.com/news/security/alleged-source-code-of-cobalt-strike-toolkit-shared-online/

https://www.darkreading.com/threat-intelligence/how-to-identify-cobalt-strike-on-your-network/a/d-id/1339357

https://www.deepinstinct.com/2021/03/18/cobalt-strike-post-exploitation-attackers-toolkit/

https://www.darkreading.com/attacks-breaches/cobalt-strike-becomes-a-preferred-hacking-tool-by-cybercrime-apt-groups/d/d-id/1341073

http://www.intel471.com/blog/cobalt-strike-cybercriminals-trickbot-qbot-hancitor

https://blog.malwarebytes.com/researchers-corner/2021/06/cobalt-strike-a-penetration-testing-tool-popular-among-criminals/

https://www.proofpoint.com/us/blog/threat-insight/cobalt-strike-favorite-tool-apt-crimeware

https://labs.sentinelone.com/hotcobalt-new-cobalt-strike-dos-vulnerability-that-lets-you-halt-operations/

https://www.intezer.com/blog/malware-analysis/cobalt-strike-detect-this-persistent-threat/

https://www.intezer.com/blog/malware-analysis/vermilionstrike-reimplementation-cobaltstrike/

https://www.recordedfuture.com/detect-cobalt-strike-inside-look/

https://elis531989.medium.com/the-squirrel-strikes-back-analysis-of-the-newly-emerged-cobalt-strike-loader-squirrelwaffle-937b73dbd9f9

https://blog.nviso.eu/2021/10/21/cobalt-strike-using-known-private-keys-to-decrypt-traffic-part-1/

https://www.cybereason.com/blog/threat-analysis-report-all-paths-lead-to-cobalt-strike-icedid-emotet-and-qbot

https://asec.ahnlab.com/en/31811/

https://unit42.paloaltonetworks.com/cobalt-strike-malleable-c2-profile/

https://unit42.paloaltonetworks.com/cobalt-strike-metadata-encoding-decoding/

https://unit42.paloaltonetworks.com/cobalt-strike-metadata-encryption-decryption/

https://securityintelligence.com/posts/analysis-rce-vulnerability-cobalt-strike/

https://cloud.google.com/blog/products/identity-security/making-cobalt-strike-harder-for-threat-actors-to-abuse

https://unit42.paloaltonetworks.com/cobalt-strike-memory-analysis/

https://securityintelligence.com/posts/defining-cobalt-strike-reflective-loader/

https://unit42.paloaltonetworks.com/cobalt-strike-malleable-c2/

https://asec.ahnlab.com/en/59110/

https://unit42.paloaltonetworks.com/attackers-exploit-public-cobalt-strike-profiles/

https://www.europol.europa.eu/media-press/newsroom/news/europol-coordinates-global-action-against-criminal-abuse-of-cobalt-strike

https://attack.mitre.org/software/S0154/

https://malpedia.caad.fkie.fraunhofer.de/details/win.cobalt_strike

https://otx.alienvault.com/browse/pulses?q=tag:Cobalt%20Strike



DoppelPaymer (category:
Malware)


type: Ransomware, Big Game Hunting

(CrowdStrike) We have dubbed this new ransomware DoppelPaymer because it shares
most of its code with the \'BitPaymer\' ransomware operated by INDRIK SPIDER.
However, there are a number of differences between DoppelPaymer and BitPaymer,
which may signify that one or more members of INDRIK SPIDER have split from the
group and forked the source code of both Dridex and BitPaymer to start their
own Big Game Hunting ransomware operation.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=6e1df6f2-f969-4cd0-bc33-e25588eb2672

https://www.crowdstrike.com/blog/doppelpaymer-ransomware-and-dridex-2/

https://malpedia.caad.fkie.fraunhofer.de/details/win.doppelpaymer

https://otx.alienvault.com/browse/pulses?q=tag:DoppelPaymer



Grief (category:
Malware)


type: Ransomware, Big Game Hunting

(Zscaler) An early Grief ransomware (aka Pay or Grief) sample was compiled on
May 17, 2021. This sample is particularly interesting because it contains the
Grief ransomware code and ransom note, but the link in the ransom note points
to the \'DoppelPaymer\' ransom portal. This suggests that the malware author may
have still been in the process of developing the Grief ransom portal.
Ransomware threat groups often rebrand the name of the malware as a diversion.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=aa2dfc3d-ed20-4970-9624-ea19b096a395

https://www.zscaler.com/blogs/security-research/doppelpaymer-continues-cause-grief-through-rebranding

https://redcanary.com/blog/grief-ransomware/

https://socradar.io/dark-web-threat-profile-grief-ransomware-group/



Source: https://andreacristaldi.github.io/APTmap/



Comments
new comment
Nobody has commented yet. Will you be the first?
 




This link is from a restricted area of the forums.
Forum



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.