{"id":3030,"date":"2021-06-08T22:15:59","date_gmt":"2021-06-09T03:15:59","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=3030"},"modified":"2021-06-08T22:16:00","modified_gmt":"2021-06-09T03:16:00","slug":"doppelpaymer-ransomware-targeting-industries","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/doppelpaymer-ransomware-targeting-industries\/","title":{"rendered":"DoppelPaymer &#8211; Ransomware targeting industries"},"content":{"rendered":"\n<p>In early December 2020, the FBI issued a warning about DoppelPaymer, a family of ransomware that first appeared in 2019 then its activities have continued in 2020, including a series of incidents in the second half of the year that they left their victims struggling to properly carry out their operations.<\/p>\n\n\n\n<p>This ransomware-type threat designed to prevent victims from accessing their files by encrypting them. In order to use their files again, victims are forced to pay a ransom to cyber criminals. Research shows that cybercriminals use DoppelPaymer in targeted attacks. It means that they target specific companies and \/ or industries. Very often, cybercriminals with a specific objective seek to infiltrate (infect) an entire network, that is, the computers used in a particular company.<\/p>\n\n\n\n<p>DoppelPaymer uses a fairly sophisticated routine, starting with infiltrating the network through malicious spam emails containing spear-phishing links or attachments designed to lure unsuspecting users into executing malicious code that is usually disguised as a document. genuine. This code is responsible for downloading other malware with more advanced capabilities (such as Emotet) onto the victim&#8217;s system. Once Emotet is downloaded, it will communicate with your command and control (C&amp;C) server to install various modules, as well as to download and run other malware.<\/p>\n\n\n\n<p>All ransom notes contain identical text. As stated therein, victims should not shut down or restart their computers, rename or delete encrypted files (and ransom notes), or attempt to restore files using any software. According to cyber criminals, such actions could lead to permanent data loss. For instructions on how to decrypt the data, victims must install Tor browser and open the link provided in each created ransom note.<\/p>\n\n\n\n<p>They mention that victims have 7 days to use the link, after which it will no longer be valid. Furthermore, it is claimed that the faster victims contact the DoppelPaymer developers, the lower the price of a decryption. The aforementioned link opens a Tor website where victims can contact cyber criminals through an online chat but &#8230; as we always say nothing ensures that your data is returned and you are only driving it financially.<\/p>\n\n\n\n<p>Most cyber criminals spread malicious programs (including ransomware) through spam campaigns, Trojans, rogue software updaters, untrustworthy software download channels \/ tools, and unofficial software &#8216;cracking&#8217; (activation) tools but indeed very often, cybercriminals send emails with attachments that, if opened, install malicious software.<\/p>\n\n\n\n<p>Examples of commonly attached files are Microsoft Office documents and PDFs, archive files such as ZIP, RAR, executable files, and JavaScript files. It is worth mentioning that they disguise such emails as if they were: important, official, etc., in order to deceive users, workers, etc.<\/p>\n\n\n\n<p>Also check:<br><a href=\"https:\/\/truxgoservers.com\/blog\/prometheus-and-grief-2-new-ransomware-groups\/\">Prometheus and Grief, 2 New Ransomware Groups<\/a><br><a href=\"https:\/\/truxgoservers.com\/blog\/epsilon-red-ransomware-targeting-microsoft\/\">Epsilon Red Ransomware targeting Microsoft<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In early December 2020, the FBI issued a warning about DoppelPaymer, a family of ransomware that first appeared in 2019 then its activities have continued in 2020, including a series of incidents in the second half of the year that they left their victims struggling to properly carry out their operations. This ransomware-type threat designed [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":3031,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10,16],"tags":[36,105],"class_list":["post-3030","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","category-ransomware","tag-cybersecurity","tag-ransomware"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>DoppelPaymer - Ransomware targeting industries - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"Companies, Industries, are mostly the targets of many cybercriminals and this is the case with the DoppelPaymer ransomware......\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/doppelpaymer-ransomware-targeting-industries\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"DoppelPaymer - Ransomware targeting industries - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"Companies, Industries, are mostly the targets of many cybercriminals and this is the case with the DoppelPaymer ransomware......\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/doppelpaymer-ransomware-targeting-industries\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-06-09T03:15:59+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-06-09T03:16:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/06\/rnsm.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"900\" \/>\n\t<meta property=\"og:image:height\" content=\"550\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/doppelpaymer-ransomware-targeting-industries\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/doppelpaymer-ransomware-targeting-industries\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"DoppelPaymer &#8211; Ransomware targeting industries\",\"datePublished\":\"2021-06-09T03:15:59+00:00\",\"dateModified\":\"2021-06-09T03:16:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/doppelpaymer-ransomware-targeting-industries\\\/\"},\"wordCount\":453,\"commentCount\":2,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/doppelpaymer-ransomware-targeting-industries\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/06\\\/rnsm.jpg\",\"keywords\":[\"Cybersecurity\",\"Ransomware\"],\"articleSection\":[\"Cybersecurity\",\"Ransomware\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/doppelpaymer-ransomware-targeting-industries\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/doppelpaymer-ransomware-targeting-industries\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/doppelpaymer-ransomware-targeting-industries\\\/\",\"name\":\"DoppelPaymer - Ransomware targeting industries - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/doppelpaymer-ransomware-targeting-industries\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/doppelpaymer-ransomware-targeting-industries\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/06\\\/rnsm.jpg\",\"datePublished\":\"2021-06-09T03:15:59+00:00\",\"dateModified\":\"2021-06-09T03:16:00+00:00\",\"description\":\"Companies, Industries, are mostly the targets of many cybercriminals and this is the case with the DoppelPaymer ransomware......\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/doppelpaymer-ransomware-targeting-industries\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/doppelpaymer-ransomware-targeting-industries\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/doppelpaymer-ransomware-targeting-industries\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/06\\\/rnsm.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/06\\\/rnsm.jpg\",\"width\":900,\"height\":550},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/doppelpaymer-ransomware-targeting-industries\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"DoppelPaymer &#8211; Ransomware targeting industries\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"DoppelPaymer - Ransomware targeting industries - Truxgo Server Blog","description":"Companies, Industries, are mostly the targets of many cybercriminals and this is the case with the DoppelPaymer ransomware......","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/doppelpaymer-ransomware-targeting-industries\/","og_locale":"es_MX","og_type":"article","og_title":"DoppelPaymer - Ransomware targeting industries - Truxgo Server Blog","og_description":"Companies, Industries, are mostly the targets of many cybercriminals and this is the case with the DoppelPaymer ransomware......","og_url":"https:\/\/truxgoservers.com\/blog\/doppelpaymer-ransomware-targeting-industries\/","og_site_name":"Truxgo Server Blog","article_published_time":"2021-06-09T03:15:59+00:00","article_modified_time":"2021-06-09T03:16:00+00:00","og_image":[{"width":900,"height":550,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/06\/rnsm.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/doppelpaymer-ransomware-targeting-industries\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/doppelpaymer-ransomware-targeting-industries\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"DoppelPaymer &#8211; Ransomware targeting industries","datePublished":"2021-06-09T03:15:59+00:00","dateModified":"2021-06-09T03:16:00+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/doppelpaymer-ransomware-targeting-industries\/"},"wordCount":453,"commentCount":2,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/doppelpaymer-ransomware-targeting-industries\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/06\/rnsm.jpg","keywords":["Cybersecurity","Ransomware"],"articleSection":["Cybersecurity","Ransomware"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/doppelpaymer-ransomware-targeting-industries\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/doppelpaymer-ransomware-targeting-industries\/","url":"https:\/\/truxgoservers.com\/blog\/doppelpaymer-ransomware-targeting-industries\/","name":"DoppelPaymer - Ransomware targeting industries - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/doppelpaymer-ransomware-targeting-industries\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/doppelpaymer-ransomware-targeting-industries\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/06\/rnsm.jpg","datePublished":"2021-06-09T03:15:59+00:00","dateModified":"2021-06-09T03:16:00+00:00","description":"Companies, Industries, are mostly the targets of many cybercriminals and this is the case with the DoppelPaymer ransomware......","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/doppelpaymer-ransomware-targeting-industries\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/doppelpaymer-ransomware-targeting-industries\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/doppelpaymer-ransomware-targeting-industries\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/06\/rnsm.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/06\/rnsm.jpg","width":900,"height":550},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/doppelpaymer-ransomware-targeting-industries\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"DoppelPaymer &#8211; Ransomware targeting industries"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3030","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=3030"}],"version-history":[{"count":3,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3030\/revisions"}],"predecessor-version":[{"id":3047,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3030\/revisions\/3047"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/3031"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=3030"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=3030"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=3030"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}