BitPaymer is a financially motivated ransomware operation active by at least 2018 that conducted extortion against corporate victims, including dozens of U.S. companies. The group is known to have relied on third-party access providers, including TA551, which supplied botnet-based access used to compromise 72 U.S. corporations between 2018 and 2019 and generate more than $14 million in extortion payments. BitPaymer is commonly discussed alongside major big-game ransomware operations such as REvil, Netwalker, and Ryuk. Operationally, BitPaymer has been associated with ransomware deployment following externally obtained initial access and with recovery inhibition behavior intended to increase victim pressure. Documented behavior includes deleting Volume Shadow Copies through native Windows administration utilities to hinder restoration from backups. Based on the supplied facts, BitPaymer is best characterized as a financially motivated ransomware actor focused on enterprise extortion.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware group that used access provided by TA551’s botnet to infect U.S. companies and extort victims.
Ransomware group that used TA551 botnet access to infect U.S. corporations and conduct extortion, resulting in over $14.17 million in payments.
Mentioned only as a comparison point to larger ransomware operations.
Ransomware that removes shadow copies to block recovery.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.