BitPaymer

S0570

Malware.View on attack.mitre.org

About this malware

BitPaymer is a ransomware variant first observed in August 2017 targeting hospitals in the U.K. BitPaymer uses a unique encryption key, ransom note, and contact information for each operation. BitPaymer has several indicators suggesting overlap with the Dridex malware and is often delivered via Dridex.

Techniques used18

Procedure examples18

TechniqueProcedure example
T1007
System Service Discovery

BitPaymer can enumerate existing Windows services on the host that are configured to run as LocalSystem.

T1012
Query Registry

BitPaymer can use the RegEnumKeyW to iterate through Registry keys.

T1018
Remote System Discovery

BitPaymer can use net view to discover remote systems.

T1027.013
Encrypted/Encoded File

BitPaymer has used RC4-encrypted strings and string hashes to avoid identifiable strings within the binary.

T1070.006
Timestomp

BitPaymer can modify the timestamp of an executable so that it can be identified and restored by the decryption tool.

T1087.001
Local Account

BitPaymer can enumerate the sessions for each user logged onto the infected host.

T1106
Native API

BitPaymer has used dynamic API resolution to avoid identifiable strings within the binary, including RegEnumKeyW.

T1112
Modify Registry

BitPaymer can set values in the Registry to help in execution.

T1134.001
Token Impersonation/Theft

BitPaymer can use the tokens of users to create processes on infected systems.

T1135
Network Share Discovery

BitPaymer can search for network shares on the domain or workgroup using net view <host>.

T1222.001
Windows Permissions

BitPaymer can use icacls /reset and takeown /F to reset a targeted executable's permissions and then take ownership.

T1480
Execution Guardrails

BitPaymer compares file names and paths to a list of excluded names and directory names during encryption.

T1486
Data Encrypted for Impact

BitPaymer can import a hard-coded RSA 1024-bit public key, generate a 128-bit RC4 key for each file, and encrypt the file in place, appending .locked to the filename.

T1490
Inhibit System Recovery

BitPaymer attempts to remove the backup shadow files from the host using vssadmin.exe Delete Shadows /All /Quiet.

T1543.003
Windows Service

BitPaymer has attempted to install itself as a service to maintain persistence.

View all 18 procedure examples

Groups that use it1

Campaigns0

None recorded.

References1

  1. Crowdstrike Indrik November 2018 Open source
    Frankoff, S., Hartley, B. (2018, November 14). Big Game Hunting: The Evolution of INDRIK SPIDER From Dridex Wire Fraud to BitPaymer Targeted Ransomware. Retrieved January 6, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.