BitPaymer

MITRE ATT&CK: S0570 View on attack.mitre.org

Aliases: wp_encrypt, FriedEx, IEncrypt, Pay OR Grief, BitPaymer, DoppelPaymer

First seen
2017-08-01 00:00:00
Malware type
ransomware
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 12:37:21

Targeted industries: healthcare-and-pharmaceutical

Targeted regions: country_code:gb

Context

BitPaymer is a ransomware variant first observed in August 2017 targeting hospitals in the U.K. BitPaymer uses a unique encryption key, ransom note, and contact information for each operation. BitPaymer has several indicators suggesting overlap with the Dridex malware and is often delivered via Dridex.

Detection coverage

  • 5 YARA rules
  • 335 Sigma rules

Malware & tools used

  • Remote System Discovery (attack-pattern)
  • Execution Guardrails (attack-pattern)
  • Windows Permissions (attack-pattern)
  • Data Encrypted for Impact (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Timestomp (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Network Share Discovery (attack-pattern)
  • Token Impersonation/Theft (attack-pattern)
  • Query Registry (attack-pattern)
  • Inhibit System Recovery (attack-pattern)
  • Windows Service (attack-pattern)
  • Bypass User Account Control (attack-pattern)
  • NTFS File Attributes (attack-pattern)
  • System Service Discovery (attack-pattern)
  • Local Account (attack-pattern)
  • Modify Registry (attack-pattern)
  • Native API (attack-pattern)

Used by threat actors

Detection rules

  • CAPE_Doppelpaymer (yara-rule)
  • MALPEDIA_Win_Doppelpaymer_Auto (yara-rule)
  • SIGNATURE_BASE_Bitpaymer_1 (yara-rule)
  • CAPE_Bitpaymer (yara-rule)
  • MALPEDIA_Win_Friedex_Auto (yara-rule)

Reports & references

  • pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
  • CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
  • CrowdStrike — Double Trouble Ransomware Data Leak Extortion Part 1 (report)
  • pwc.co.uk — Cyber Threats 2019 Retrospect (report)
  • CrowdStrike — Big Game Hunting The Evolution Of Indrik Spider From Dridex Wire Fraud To Bitpaymer Targeted Ransomware (report)
  • secureworks.com — Gold Heron (report)
  • CrowdStrike — Report2021Gtr (report)
  • secureworks.com — Gold Drake (report)
  • Microsoft — Human Operated Ransomware Attacks A Preventable Disaster (report)
  • CrowdStrike — Hades Ransomware Successor To Indrik Spiders Wastedlocker (report)
  • CrowdStrike — How Big Game Hunting Ttps Shifted After Darkside Pipeline Attack (report)
  • cisoclub.ru — Otchet Kompanii Group Ib Ransomware Uncovered 2020 2021 (report)
  • docs.google.com — 1Mi8Z2Tbhmqq5X8Wf Ozv3Dvjz5Sjos 3 (report)
  • i.blackhat.com — Eu 20 Clarke Its Not Finished The Evolving Maturity In Ransomware Operations Wp (report)
  • i.blackhat.com — Eu 20 Clarke Its Not Finished The Evolving Maturity In Ransomware Operations (report)
  • jsac.jpcert.or.jp — Jsac2020 1 Tamada Yamazaki Nakatsuru En (report)
  • ke-la.com — How Ransomware Gangs Find New Monetization Schemes And Evolve In Marketing (report)
  • ke-la.com — To Attack Or Not To Attack Targeting The Healthcare Sector In The Underground Ecosystem (report)
  • ke-la.com — Zooming Into Darknet Threats Targeting Jp Orgs Kela (report)
  • krebsonsecurity.com — Ransomware Gangs And The Name Game Distraction (report)
  • public.intel471.com — Ransomware As A Service 2020 Ryuk Maze Revil Egregor Doppelpaymer (report)
  • sites.temple.edu — Ci Rw Attacks (report)
  • Broadcom/Symantec — The Ransomware Threat September 2021 (report)
  • vulnerability.ch — Ransomware And Date Leak Site Publication Time Analysis (report)
  • web.archive.org — Otchet Kompanii Group Ib Ransomware Uncovered 2020 2021 (report)

External references