BitPaymer
MITRE ATT&CK: S0570 View on attack.mitre.org
Aliases: wp_encrypt, FriedEx, IEncrypt, Pay OR Grief, BitPaymer, DoppelPaymer
- First seen
- 2017-08-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 12:37:21
Targeted industries: healthcare-and-pharmaceutical
Targeted regions: country_code:gb
Context
BitPaymer is a ransomware variant first observed in August 2017 targeting hospitals in the U.K. BitPaymer uses a unique encryption key, ransom note, and contact information for each operation. BitPaymer has several indicators suggesting overlap with the Dridex malware and is often delivered via Dridex.
Detection coverage
- 5 YARA rules
- 335 Sigma rules
Malware & tools used
- Remote System Discovery (attack-pattern)
- Execution Guardrails (attack-pattern)
- Windows Permissions (attack-pattern)
- Data Encrypted for Impact (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Timestomp (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Network Share Discovery (attack-pattern)
- Token Impersonation/Theft (attack-pattern)
- Query Registry (attack-pattern)
- Inhibit System Recovery (attack-pattern)
- Windows Service (attack-pattern)
- Bypass User Account Control (attack-pattern)
- NTFS File Attributes (attack-pattern)
- System Service Discovery (attack-pattern)
- Local Account (attack-pattern)
- Modify Registry (attack-pattern)
- Native API (attack-pattern)
Used by threat actors
- Indrik Spider (threat-actor)
Detection rules
- CAPE_Doppelpaymer (yara-rule)
- MALPEDIA_Win_Doppelpaymer_Auto (yara-rule)
- SIGNATURE_BASE_Bitpaymer_1 (yara-rule)
- CAPE_Bitpaymer (yara-rule)
- MALPEDIA_Win_Friedex_Auto (yara-rule)
Reports & references
- pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
- CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
- CrowdStrike — Double Trouble Ransomware Data Leak Extortion Part 1 (report)
- pwc.co.uk — Cyber Threats 2019 Retrospect (report)
- CrowdStrike — Big Game Hunting The Evolution Of Indrik Spider From Dridex Wire Fraud To Bitpaymer Targeted Ransomware (report)
- secureworks.com — Gold Heron (report)
- CrowdStrike — Report2021Gtr (report)
- secureworks.com — Gold Drake (report)
- Microsoft — Human Operated Ransomware Attacks A Preventable Disaster (report)
- CrowdStrike — Hades Ransomware Successor To Indrik Spiders Wastedlocker (report)
- CrowdStrike — How Big Game Hunting Ttps Shifted After Darkside Pipeline Attack (report)
- cisoclub.ru — Otchet Kompanii Group Ib Ransomware Uncovered 2020 2021 (report)
- docs.google.com — 1Mi8Z2Tbhmqq5X8Wf Ozv3Dvjz5Sjos 3 (report)
- i.blackhat.com — Eu 20 Clarke Its Not Finished The Evolving Maturity In Ransomware Operations Wp (report)
- i.blackhat.com — Eu 20 Clarke Its Not Finished The Evolving Maturity In Ransomware Operations (report)
- jsac.jpcert.or.jp — Jsac2020 1 Tamada Yamazaki Nakatsuru En (report)
- ke-la.com — How Ransomware Gangs Find New Monetization Schemes And Evolve In Marketing (report)
- ke-la.com — To Attack Or Not To Attack Targeting The Healthcare Sector In The Underground Ecosystem (report)
- ke-la.com — Zooming Into Darknet Threats Targeting Jp Orgs Kela (report)
- krebsonsecurity.com — Ransomware Gangs And The Name Game Distraction (report)
- public.intel471.com — Ransomware As A Service 2020 Ryuk Maze Revil Egregor Doppelpaymer (report)
- sites.temple.edu — Ci Rw Attacks (report)
- Broadcom/Symantec — The Ransomware Threat September 2021 (report)
- vulnerability.ch — Ransomware And Date Leak Site Publication Time Analysis (report)
- web.archive.org — Otchet Kompanii Group Ib Ransomware Uncovered 2020 2021 (report)