Netskope Threat Labs

BitPaymer

ATP Sandbox Adv. HeuristicsAV

BitPaymer is a ransomware variant first observed in August 2017 targeting hospitals in the United Kingdom. It generates a unique encryption key, ransom note, and contact information for each operation, and its indicators overlap with the Dridex malware, whose crews often deliver it.

First seen
March 2022
Last seen
October 2026
Bitpaymer

18 techniques across 7 tactics.

TA0002 Execution

TA0003 Persistence

  • T1543Create or Modify System Process
  • T1547Boot or Logon Autostart Execution

TA0004 Privilege Escalation

  • T1548Abuse Elevation Control Mechanism

TA0005 Stealth

TA0007 Discovery

TA0040 Impact

  • T1486Data Encrypted for Impact
  • T1490Inhibit System Recovery

TA0112 Defense Impairment

  • T1112Modify Registry
  • T1222File and Directory Permissions Modification
Alert Name
DeepScan:Generic.Ransom.Bitpaymer.06BE0086
Dump:Generic.Ransom.Bitpaymer.06BE0086
Dump:Trojan.Ransom.BitPaymer.C
Gen:Variant.Ransom.BitPaymer.2
Generic.Ransom.Bitpaymer.0284916B
MemScan:Trojan.Ransom.BitPaymer.C
Trojan.Ransom.BitPaymer.C
Win32.Ransomware.BitPaymer