BitPaymer, also known as FriedEx and WP_Encrypt, is a Windows ransomware family associated with Evil Corp and closely linked in multiple analyses to the Dridex ecosystem. It emerged in 2017 and became notable for targeted intrusions against higher-value organizations rather than indiscriminate consumer infections. Security reporting has described substantial code overlap between BitPaymer and Dridex, including shared obfuscation and API-resolution approaches, and has assessed that the same developers were responsible for both malware families. DoppelPaymer is widely regarded as an offshoot or fork derived from BitPaymer.
BitPaymer encrypts victim files and drops ransom-related information for recovery instructions. Reported cryptographic implementations include per-file symmetric encryption protected by an embedded RSA public key. The malware has also been observed copying itself into an NTFS alternate data stream as a concealment measure, dynamically resolving Windows APIs to reduce static detection opportunities, and modifying the Windows Registry to support execution. It can establish persistence through Registry Run keys and has been documented using a UAC bypass technique involving Registry hijacking and execution through a trusted Windows management component to obtain elevated privileges.
For network-aware operation inside enterprise environments, BitPaymer can enumerate network shares using native Windows commands, supporting propagation of impact across accessible shared resources. Operational reporting has repeatedly placed BitPaymer in the broader trend of manually deployed, post-compromise ransomware used after initial access obtained through other malware or exposed remote services. Delivery and access patterns associated with BitPaymer operations have included brute-force compromise of Remote Desktop Protocol services, and BitPaymer has also appeared as a later-stage payload delivered through other crimeware ecosystems such as Dridex and Emotet.
BitPaymer is part of the evolution of Evil Corp from banking malware into targeted ransomware operations. It was used in attacks through 2019 and later gave rise to related families in the same criminal lineage, including DoppelPaymer and subsequently WastedLocker-era activity linked to the same actor set.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
For example, a vulnerability in Apple WebKitGTK (CVE-2019-8720) received a CVE from Red Hat in October 2019 was added to the KEV catalog in March because it was being exploited by BitPaymer ransomware.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Code for BitPaymer, also known as Friedex, includes numerous similarities to Dridex, despite its function as ransomware rather than data extraction.
Code for BitPaymer, also known as Friedex, includes numerous similarities to Dridex, despite its function as ransomware rather than data extraction.
BitPaymer, a ransomware variant operated by the threat actor with the self-styled name “Evil Corp” (a.k.a. the Dridex Group), was first introduced in 2017.
...as well as several ransomware strains including Locky, BitPaymer, Philadelphia, GlobeImposter, and Jaff on their targets' computers...
From 2018 to 2019, TA551 gave the BitPaymer ransomware group access to its botnet, helping infect 72 U.S. companies and generate over $14.17 million in extortion payments.
"From July 2017 to early 2020, GOLD DRAKE developed and distributed the BitPaymer ransomware during post-intrusion attacks facilitated by Dridex."
35 distinct techniques documented for this family, organized by ATT&CK tactic.
3.3 Point d’eau ... L’infection, par point d’eau ou par courriel d’hameçonnage pointant vers une URL malveillante, consiste en l’apparition d’une fausse mise à jour de navigateur, qui conduirait à l’installation du code malveillant FakeUpdates, puis de la propagation de Dridex
Initial Access Trusted Relationship Subcontractors or ESN compromises
Actors typically distribute Dridex malware through phishing e-mail spam campaigns.
Execution Command-Line Interface arp / nslookup / etc.
Bitpaymer adds a .cmd file to the registry key (“HKCU\Software\Classes\mscfile\shell\open\command”)... and that, in turn, executes the .cmd file that runs the ransomware binary.
ADVSTORESHELL is capable of setting and deleting Registry values. Agent Tesla can achieve persistence by modifying Registry key entries. APT41 used a malware variant called GOODLUCK to modify the registry in order to steal credentials.
BitPaymer can suppress UAC prompts by setting the HKCU\Software\Classes\ms-settings\shell\open\command registry key on Windows 10 or HKCU\Software\Classes\mscfile\shell\open\command on Windows 7... LockBit 2.0 can bypass UAC through creating the Registry key HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ICM\Calibration.
Privilege Escalation Exploitation for Privilege Escalation Apple Update 0-day
BitPaymer can suppress UAC prompts by setting the HKCU\Software\Classes\ms-settings\shell\open\command registry key on Windows 10 or HKCU\Software\Classes\mscfile\shell\open\command on Windows 7... LockBit 2.0 can bypass UAC through creating the Registry key HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ICM\Calibration.
The content repeatedly describes malware and threat actors that 'bypass UAC,' 'perform UAC bypass,' or use specific Windows components such as fodhelper.exe, eventvwr.exe, sdclt.exe, CMSTPLUA COM interface, SilentCleanup, and registry hijacks to gain elevated privileges.
BitPaymer has used dynamic API resolution to avoid identifiable strings within the binary, including RegEnumKeyW.
It’s also worth mentioning that both Dridex and FriedEx use the same malware packer.
It resolves all system API calls on the fly by searching for them by hash...
Backups were either encrypted or deleted or backup disks were formatted. Shadow copies also removed
Defense evasion Deobfuscate/Decode Files or Information
Defense evasion Exploitation for Defense Evasion Windows Defender
The malware finds a clean system file, copies itself to the clean file’s ADS, and then executes itself as a service component of the clean file. This makes it appear that the clean file is the source of the ransomware behavior.
The response can be a simple acknowledgment or a longer set of instructions, a module or executable... In many cases the C2 server response only contains an updated version of the binary... If the victim is infected with the latest version of Emotet... the latest modules are downloaded.
The Grief Ransomware Gang ... claims to have infected 41 new victims ... with their ransomware.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
100 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware family mentioned as one of the strains transacting with Stern.
Ransomware used in attacks against U.S. companies after operators obtained access via the TA551/Mario Kart botnet.
Ransomware used in attacks against at least 72 U.S. companies via access provided by the phishing botnet managed by Angelov's group.
Ransomware that encrypts or locks victims out of their systems and demands cryptocurrency payment to restore access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.