Ransomware Group intelligence
Bitpaymer
InactiveTrack Bitpaymer with 9 published victims in a single intelligence view.
Overview
Bitpaymer is tracked by Breach House as a ransomware group with 9 published victims.
United States is currently the most targeted country in this dataset.
No leak location metadata is currently available for this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (0)
No known leak locations available for this group.
Top Activity Sectors (3)
Typical Attacks (18)
▼How Bitpaymer typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via BitPaymer.
-
T1106 Native API Execution
What they do: BitPaymer has used dynamic API resolution to avoid identifiable strings within the binary, including RegEnumKeyW.
What that means: Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
-
What they do: BitPaymer can set values in the Registry to help in execution.
What that means: Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
-
What they do: BitPaymer has attempted to install itself as a service to maintain persistence.
What that means: Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence.
-
What they do: BitPaymer has set the run key HKCU\Software\Microsoft\Windows\CurrentVersion\Run for persistence.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
What they do: BitPaymer can use the tokens of users to create processes on infected systems.
What that means: Adversaries may duplicate then impersonate another user's existing token to escalate privileges and bypass access controls.
-
T1548.002 Bypass User Account Control Privilege Escalation
What they do: BitPaymer can suppress UAC prompts by setting the HKCU\Software\Classes\ms-settings\shell\open\command registry key on Windows 10 or HKCU\Software\Classes\mscfile\shell\open\command on Windows 7 and launching the eventvwr.msc process, which launches BitPaymer with elevated privileges.
What that means: Adversaries may bypass UAC mechanisms to elevate process privileges on system.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: BitPaymer has used RC4-encrypted strings and string hashes to avoid identifiable strings within the binary.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1070.006 Timestomp Stealth
What they do: BitPaymer can modify the timestamp of an executable so that it can be identified and restored by the decryption tool.
What that means: Adversaries may modify file time attributes to hide new files or changes to existing files.
-
T1480 Execution Guardrails Stealth
What they do: BitPaymer compares file names and paths to a list of excluded names and directory names during encryption.
What that means: Adversaries may use execution guardrails to constrain execution or actions based on adversary supplied and environment specific conditions that are expected to be present on the target.
-
T1564.004 NTFS File Attributes Stealth
What they do: BitPaymer has copied itself to the :bin alternate data stream of a newly created file.
What that means: Adversaries may use NTFS file attributes to hide their malicious data in order to evade detection.
-
T1222.001 Windows Permissions Defense Impairment
What they do: BitPaymer can use icacls /reset and takeown /F to reset a targeted executable's permissions and then take ownership.
What that means: Adversaries may modify file or directory permissions/attributes to evade access control lists (ACLs) and access protected files.
-
T1007 System Service Discovery Discovery
What they do: BitPaymer can enumerate existing Windows services on the host that are configured to run as LocalSystem.
What that means: Adversaries may try to gather information about registered local system services.
-
T1012 Query Registry Discovery
What they do: BitPaymer can use the RegEnumKeyW to iterate through Registry keys.
What that means: Adversaries may interact with the Windows Registry to gather information about the system, configuration, and installed software.
-
T1018 Remote System Discovery Discovery
What they do: BitPaymer can use net view to discover remote systems.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1087.001 Local Account Discovery
What they do: BitPaymer can enumerate the sessions for each user logged onto the infected host.
What that means: Adversaries may attempt to get a listing of local system accounts.
-
T1135 Network Share Discovery Discovery
What they do: BitPaymer can search for network shares on the domain or workgroup using net view <host>.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1486 Data Encrypted for Impact Impact
What they do: BitPaymer can import a hard-coded RSA 1024-bit public key, generate a 128-bit RC4 key for each file, and encrypt the file in place, appending .locked to the filename.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: BitPaymer attempts to remove the backup shadow files from the host using vssadmin.exe Delete Shadows /All /Quiet.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Ransom Notes (2)
▼The note this group leaves on a compromised machine. Click a filename to read it.
bitpaymer_v1.txt
YOUR COMPANY HAS BEEN SUCCESSFULLY PENETRATED!
All files are encrypted. We accept only bitcoins to share the decryption software for your network.
Also, we have gathered all your private sensitive data.
So if you decide not to pay anytime soon, we would share with media’s.
It may harm your business reputation and the company’s capitalization fell sharply.
Do not try to do it with 3rd-parties programs, files might be damaged then.
Decrypting of your files is only possible with the special decryption software.
To receive your private key and the decryption software please follow the link (using tor2web service):
https://qmnmrba4s4a3py6z.onion/order/[snip]
If this address is not available, follow these steps:
1. Download and install Tor Browser: https://www.torproject.org/proiects/torbrowser.html.en
2. After a successful installation, run the browser and wait for in tialization.
3. Type in the address bar: https://qmnmrba4s4a3py6z.onion/order/[snip]
4. Follow the instructions on the site
5. This link is valid for 72 hours only. Afetr that period your local data would be lost completely.
6. Any questions: [email protected]
bitpaymer_v2.txt
Hello [snip], Your network was hacked and encrypted. No free decryption software is available on the web. Email us at [email protected], [email protected], [email protected] (or) [email protected], [email protected], [email protected] to get the ransom amount. Please, use your company name as the email subject. TAIL:[snip] KEY:[snip]
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (9)
Search, filter and paginate the victim timeline for Bitpaymer. Showing 1–9 of 9.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Petróleos Mexicanos (Pemex) id296 View details | Mexico | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Everis id295 View details | Spain | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Pilz id288 View details | Germany | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | M6 id287 View details | France | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Arizona Beverages id264 View details | United States | Hospitality / Food & Beverage / Tourism | — | |
|
No additional victim description available. |
|||||
| Ransomware | KrausMaffei id256 View details | Germany | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | PGA id251 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Borough of Matanuska-Susitna (Mat-Su) id249 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | NHS Lanarkshire board hospitals id234 View details | Healthcare / Pharma | — | ||
|
No additional victim description available. |
|||||