logo

Operation DoppelBrand: Massive Fortune 500 Brand Impersonation Campaign Uncovered

ID: a0eb48b5-2479-5b6b-9285-bc7d1eeaf8c0

STIX ID: report--a0eb48b5-2479-5b6b-9285-bc7d1eeaf8c0

Feed Name: SOCRadar Blog

Threat Score
78/100

Date Published: 2026-02-16

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

SOCRadar uncovered Operation DoppelBrand, a multi-year, financially-motivated credential theft campaign operated by GS7 that impersonates major financial and technology brands to phish employees and customers of Fortune 500 companies; the actor automates domain deployment, exfiltrates credentials to Telegram bots in real time, and installs legitimate Remote Monitoring and Management tools to gain persistent access for resale or follow-on attacks (including ransomware), with hundreds of malicious domains and observed bitcoin transactions tied to campaign activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.