Description
BitPaymer is a ransomware variant first observed in August 2017 targeting hospitals in the United Kingdom. It generates a unique encryption key, ransom note, and contact information for each operation, and its indicators overlap with the Dridex malware, whose crews often deliver it.
Stats
- First seen
- March 2022
- Last seen
- October 2026
Also known as
Bitpaymer
MITRE ATT&CK techniques
18 techniques across 7 tactics.
TA0002 Execution
- T1106Native API
TA0003 Persistence
TA0004 Privilege Escalation
TA0005 Stealth
TA0007 Discovery
Associated groups
Alert name variants
| Alert Name |
|---|
| DeepScan:Generic.Ransom.Bitpaymer.06BE0086 |
| Dump:Generic.Ransom.Bitpaymer.06BE0086 |
| Dump:Trojan.Ransom.BitPaymer.C |
| Gen:Variant.Ransom.BitPaymer.2 |
| Generic.Ransom.Bitpaymer.0284916B |
| MemScan:Trojan.Ransom.BitPaymer.C |
| Trojan.Ransom.BitPaymer.C |
| Win32.Ransomware.BitPaymer |