INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Operation DoppelBrand Weaponizes Fortune 500 Brands

| 2026-02-16 18:05 CRITICAL HIGH
Executive Summary AI-generated
GS7, a sophisticated and elusive threat actor, has been targeting Fortune 500 companies in a broad phishing campaign that turns the company's own brands against them. The group, which has remained active for nearly a decade, consistently rotates its phishing infrastructure to mimic legitimate login portals, replicating official branding with unprecedented accuracy. GS7 may even act as an initial access broker selling access to infrastructure to ransomware groups or other affiliates. This campaign is ongoing and has been observed between December and January, with the group's history stretching back to 2022.
Technical Mitigations AI-generated
* Implement robust password policies and multi-factor authentication to prevent attackers from gaining access through compromised credentials. * Regularly update software, operating systems, and applications to ensure they have the latest security patches and features. * Use secure communication channels (e.g. HTTPS) when transmitting sensitive information or accessing websites that may be impersonated by GS7. * Educate users about phishing attacks and how to identify suspicious emails or links; provide guidance on safe browsing practices. * Monitor for signs of compromised accounts, such as unusual login activity or changes in account settings, and take action to secure affected accounts.
Technical Observables
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence distributed on:
Incident Link
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation DoppelBrandOperation DoppelBrand Lazarus GroupLazarus Group Medusa RansomwareMedusa Ransomware
Target & Sectors
EUROPE EUROPE NORTH_AMERICA NORTH_AMERICA healthcarehealthcare technologytechnology telecommunicationstelecommunications
Incident Timeline
December 2025
Threat actors used compromised infrastructure linked to earlier activity dating back to 2022 to target Wells Fargo and USAA.
organisation Wells Fargo
organisation USAA
general_metric 500 companies
campaign Operation DoppelBrand
January 2026
Threat actors used compromised infrastructure linked to earlier activity dating back to 2022 to target Wells Fargo and USAA.
organisation Wells Fargo
organisation USAA
general_metric 500 companies
campaign Operation DoppelBrand
2026-02-16
GS7 deployed legitimate remote access software such as LogMeIn Resolve to establish unattended access.
organisation SOCRadar
organisation Credential Theft GS7
organisation Wells Fargo
organisation USAA
organisation Navy Federal Credit Union
organisation Fidelity Investments
organisation Citibank
organisation Fidelity
organisation Telegram
organisation CSS
organisation Operation DoppelBrand
organisation Credential Theft
organisation IAB
threat_actor Lazarus Group
organisation DoppelBrand
organisation NameCheap
organisation OwnRegistrar
organisation Cloudflare
infrastructure 150 malicious domains
organisation SSL
organisation Infrastructure Built for Scale SOCRadar
infrastructure 200 additional domains
organisation Evolving Initial Access Broker Activity
organisation IP
organisation GS
organisation RMM
organisation MFA
organisation MSI
organisation OneDrive
organisation Remote Access and Monetization Beyond
organisation BTC
February 16
Threat actors used lookalike domains and cloned login portals to target Fortune 500 brands.
industry Technology
Tactical Metrics
Metrics
infrastructure
150
Malicious Domains
Metrics
infrastructure
200
Additional Domains
Intelligence Sources
Dark Reading 2026-02-16
Infosecurity-Magazine 2026-02-16