BitPaymer, also known as FriedEx and WP_Encrypt, is a Windows ransomware family associated with the Evil Corp cybercrime group and closely linked in development lineage to Dridex. First observed in 2017, it was used in targeted intrusions against higher-profile organizations rather than broad consumer-focused campaigns. Multiple analyses have identified substantial code overlap and shared development characteristics between BitPaymer and Dridex, supporting assessment that the same developers or closely related operators were involved. DoppelPaymer later emerged as an offshoot or fork of BitPaymer.
BitPaymer encrypts victim files and uses asymmetric cryptography to protect per-file or per-victim encryption material. It has been associated with ransom-note generation on infected systems and with enterprise-impacting attacks. Reported targeting and deployment patterns indicate use in post-compromise ransomware operations, including attacks against corporate environments and network-accessible resources.
The malware supports several defense-evasion and post-exploitation behaviors beyond file encryption. It has copied itself into NTFS alternate data streams for concealment, used dynamic API resolution to hinder static analysis, modified the Windows Registry to assist execution, and established persistence through Registry Run keys. BitPaymer has also been observed suppressing UAC prompts through a registry-hijack-based bypass technique to obtain elevated execution on Windows systems.
For internal network operations, BitPaymer can enumerate network shares using native Windows functionality, enabling discovery of accessible domain or workgroup resources prior to or during encryption activity. Delivery and access patterns reported around BitPaymer include targeted deployment following earlier compromise by other malware families, and some reporting has described distribution via brute-forced remote access services in enterprise environments. The family is widely regarded as part of the evolution of Evil Corp from banking malware operations centered on Dridex into targeted ransomware campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
For example, a vulnerability in Apple WebKitGTK (CVE-2019-8720) received a CVE from Red Hat in October 2019 was added to the KEV catalog in March because it was being exploited by BitPaymer ransomware.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Code for BitPaymer, also known as Friedex, includes numerous similarities to Dridex, despite its function as ransomware rather than data extraction.
Code for BitPaymer, also known as Friedex, includes numerous similarities to Dridex, despite its function as ransomware rather than data extraction.
BitPaymer, a ransomware variant operated by the threat actor with the self-styled name “Evil Corp” (a.k.a. the Dridex Group), was first introduced in 2017.
...as well as several ransomware strains including Locky, BitPaymer, Philadelphia, GlobeImposter, and Jaff on their targets' computers...
From 2018 to 2019, TA551 gave the BitPaymer ransomware group access to its botnet, helping infect 72 U.S. companies and generate over $14.17 million in extortion payments.
"From July 2017 to early 2020, GOLD DRAKE developed and distributed the BitPaymer ransomware during post-intrusion attacks facilitated by Dridex."
36 distinct techniques documented for this family, organized by ATT&CK tactic.
3.3 Point d’eau ... L’infection, par point d’eau ou par courriel d’hameçonnage pointant vers une URL malveillante, consiste en l’apparition d’une fausse mise à jour de navigateur, qui conduirait à l’installation du code malveillant FakeUpdates, puis de la propagation de Dridex
Initial Access Trusted Relationship Subcontractors or ESN compromises
Actors typically distribute Dridex malware through phishing e-mail spam campaigns.
Execution Command-Line Interface arp / nslookup / etc.
Bitpaymer adds a .cmd file to the registry key (“HKCU\Software\Classes\mscfile\shell\open\command”)... and that, in turn, executes the .cmd file that runs the ransomware binary.
ADVSTORESHELL is capable of setting and deleting Registry values. Agent Tesla can achieve persistence by modifying Registry key entries. APT41 used a malware variant called GOODLUCK to modify the registry in order to steal credentials.
BitPaymer can suppress UAC prompts by setting the HKCU\Software\Classes\ms-settings\shell\open\command registry key on Windows 10 or HKCU\Software\Classes\mscfile\shell\open\command on Windows 7... LockBit 2.0 can bypass UAC through creating the Registry key HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ICM\Calibration.
Privilege Escalation Exploitation for Privilege Escalation Apple Update 0-day
BitPaymer can suppress UAC prompts by setting the HKCU\Software\Classes\ms-settings\shell\open\command registry key on Windows 10 or HKCU\Software\Classes\mscfile\shell\open\command on Windows 7... LockBit 2.0 can bypass UAC through creating the Registry key HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ICM\Calibration.
The content repeatedly describes malware and threat actors that 'bypass UAC,' 'perform UAC bypass,' or use specific Windows components such as fodhelper.exe, eventvwr.exe, sdclt.exe, CMSTPLUA COM interface, SilentCleanup, and registry hijacks to gain elevated privileges.
BitPaymer has used dynamic API resolution to avoid identifiable strings within the binary, including RegEnumKeyW.
It’s also worth mentioning that both Dridex and FriedEx use the same malware packer.
It resolves all system API calls on the fly by searching for them by hash...
Backups were either encrypted or deleted or backup disks were formatted. Shadow copies also removed
Defense evasion Deobfuscate/Decode Files or Information
Defense evasion Exploitation for Defense Evasion Windows Defender
The malware finds a clean system file, copies itself to the clean file’s ADS, and then executes itself as a service component of the clean file. This makes it appear that the clean file is the source of the ransomware behavior.
The malware finds a clean system file, copies itself to the clean file’s ADS, and then executes itself as a service component of the clean file.
The response can be a simple acknowledgment or a longer set of instructions, a module or executable... In many cases the C2 server response only contains an updated version of the binary... If the victim is infected with the latest version of Emotet... the latest modules are downloaded.
When encrypting a victim's systems, Hades creates a ransom note named 'HOW-TO-DECRYPT-[extension].txt' resembling ransom notes dropped by REvil ransomware.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
99 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware family mentioned as one of the strains transacting with Stern.
Ransomware used in attacks against U.S. companies after operators obtained access via the TA551/Mario Kart botnet.
Ransomware used in attacks against at least 72 U.S. companies via access provided by the phishing botnet managed by Angelov's group.
Ransomware that encrypts or locks victims out of their systems and demands cryptocurrency payment to restore access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.