BitPaymer, also known as Friedex, is Windows ransomware associated with Evil Corp, also tracked as INDRIK SPIDER. It came to prominence in 2017 and was used in targeted, high-value enterprise ransomware operations commonly termed big game hunting. Operators deployed it through access established by Dridex infections, including against domain-controlled systems. Its campaigns affected organizations primarily in North America, particularly the United States, and Western Europe, including financial institutions.
BitPaymer encrypts files in place using a separate 128-bit RC4 key for each file and an embedded RSA-1024 public key as part of its encryption scheme. It can enumerate remote systems and network shares in domains or workgroups using native Windows networking utilities. Defense-evasion behaviors include copying itself into an NTFS alternate data stream and dynamically resolving Windows APIs to reduce identifiable strings in its executable. It also modifies the Windows Registry to support execution and can bypass User Account Control on Windows 7 and Windows 10 to execute with elevated privileges.
BitPaymer shares substantial code and implementation similarities with Dridex, but its primary purpose is encrypting data for ransom rather than stealing banking information. DoppelPaymer emerged in 2019 as a fork of BitPaymer.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
For example, a vulnerability in Apple WebKitGTK (CVE-2019-8720) received a CVE from Red Hat in October 2019 was added to the KEV catalog in March because it was being exploited by BitPaymer ransomware.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Indrik Spider has encrypted domain-controlled systems using BitPaymer.
Code for BitPaymer, also known as Friedex, includes numerous similarities to Dridex, despite its function as ransomware rather than data extraction.
BitPaymer, a ransomware variant operated by the threat actor with the self-styled name “Evil Corp” (a.k.a. the Dridex Group), was first introduced in 2017.
...as well as several ransomware strains including Locky, BitPaymer, Philadelphia, GlobeImposter, and Jaff on their targets' computers...
From 2018 to 2019, TA551 gave the BitPaymer ransomware group access to its botnet, helping infect 72 U.S. companies and generate over $14.17 million in extortion payments.
"From July 2017 to early 2020, GOLD DRAKE developed and distributed the BitPaymer ransomware during post-intrusion attacks facilitated by Dridex."
23 distinct techniques documented for this family, organized by ATT&CK tactic.
ADVSTORESHELL is capable of setting and deleting Registry values. Agent Tesla can achieve persistence by modifying Registry key entries. APT41 used a malware variant called GOODLUCK to modify the registry in order to steal credentials.
BitPaymer can suppress UAC prompts by setting the HKCU\Software\Classes\ms-settings\shell\open\command registry key on Windows 10 or HKCU\Software\Classes\mscfile\shell\open\command on Windows 7... LockBit 2.0 can bypass UAC through creating the Registry key HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ICM\Calibration.
BitPaymer can suppress UAC prompts by setting the HKCU\Software\Classes\ms-settings\shell\open\command registry key on Windows 10 or HKCU\Software\Classes\mscfile\shell\open\command on Windows 7... LockBit 2.0 can bypass UAC through creating the Registry key HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ICM\Calibration.
The content repeatedly describes malware and threat actors that 'bypass UAC,' 'perform UAC bypass,' or use specific Windows components such as fodhelper.exe, eventvwr.exe, sdclt.exe, CMSTPLUA COM interface, SilentCleanup, and registry hijacks to gain elevated privileges.
The response can be a simple acknowledgment or a longer set of instructions, a module or executable... In many cases the C2 server response only contains an updated version of the binary... If the victim is infected with the latest version of Emotet... the latest modules are downloaded.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
109 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware family mentioned as one of the strains transacting with Stern.
Ransomware used in attacks against U.S. companies after operators obtained access via the TA551/Mario Kart botnet.
Ransomware used in attacks against at least 72 U.S. companies via access provided by the phishing botnet managed by Angelov's group.
Ransomware that encrypts or locks victims out of their systems and demands cryptocurrency payment to restore access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.