Malware.View on attack.mitre.org
BitPaymer is a ransomware variant first observed in August 2017 targeting hospitals in the U.K. BitPaymer uses a unique encryption key, ransom note, and contact information for each operation. BitPaymer has several indicators suggesting overlap with the Dridex malware and is often delivered via Dridex.
| Technique | Procedure example |
|---|---|
| T1007 System Service Discovery |
BitPaymer can enumerate existing Windows services on the host that are configured to run as LocalSystem. |
| T1012 Query Registry |
BitPaymer can use the RegEnumKeyW to iterate through Registry keys. |
| T1018 Remote System Discovery |
BitPaymer can use |
| T1027.013 Encrypted/Encoded File |
BitPaymer has used RC4-encrypted strings and string hashes to avoid identifiable strings within the binary. |
| T1070.006 Timestomp |
BitPaymer can modify the timestamp of an executable so that it can be identified and restored by the decryption tool. |
| T1087.001 Local Account |
BitPaymer can enumerate the sessions for each user logged onto the infected host. |
| T1106 Native API |
BitPaymer has used dynamic API resolution to avoid identifiable strings within the binary, including |
| T1112 Modify Registry |
BitPaymer can set values in the Registry to help in execution. |
| T1134.001 Token Impersonation/Theft |
BitPaymer can use the tokens of users to create processes on infected systems. |
| T1135 Network Share Discovery |
BitPaymer can search for network shares on the domain or workgroup using |
| T1222.001 Windows Permissions |
BitPaymer can use |
| T1480 Execution Guardrails |
BitPaymer compares file names and paths to a list of excluded names and directory names during encryption. |
| T1486 Data Encrypted for Impact |
BitPaymer can import a hard-coded RSA 1024-bit public key, generate a 128-bit RC4 key for each file, and encrypt the file in place, appending |
| T1490 Inhibit System Recovery |
BitPaymer attempts to remove the backup shadow files from the host using |
| T1543.003 Windows Service |
BitPaymer has attempted to install itself as a service to maintain persistence. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.