Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

7/15/2019
04:25 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

Meet DoppelPaymer, BitPaymer's Ransomware Lookalike

New ransomware variant DoppelPaymer was leveraged in campaigns against the City of Edcouch, Texas, and the Chilean Ministry of Agriculture.

Researchers have identified a new ransomware variant dubbed DoppelPaymer, named for code similarities it shares with BitPaymer ransomware operated by the Indrik Spider attack group.

The new variant was spotted in a series of ransomware campaigns starting in June 2019, including attacks against the City of Edcouch, Texas, as well as the Chilean Ministry of Agriculture, CrowdStrike researchers report in a blog post on the malware discovery.

While most of their source code is related, differences between BitPaymer and DoppelPaymer could indicate a member of Indrik Spider splintered from the group and forked BitPaymer and Dridex source code to begin a "big game hunting" ransomware operation. Big game hunting is a term CrowdStrike uses to describe the tactic of targeting organizations for large payouts.

"Big game hunters favor municipalities, industrial/manufacturing, healthcare, and targets which cannot accept downtime," says Adam Meyers, vice president of intelligence at CrowdStrike, adding that in this case, researchers saw targets across multiple verticals. "They choose targets in these verticals to increase the likelihood of payment, likely thinking that these victims are not prepared to recover and the cost of ransom is less than the cost of downtime."

Indrik Spider was formed in 2014 by former affiliates of the GameOver Zeus criminal network. Shortly after its inception, the group built Dridex, which became one of the world's most prominent cybercrime operations in 2015 and 2016. In August 2017, it launched BitPaymer and began the shift to big game hunting, using access to an organization to demand more money.

Since BitPaymer launched, Indrik Spider has made several changes to its original source code. November 2018 brought a significant update: the ransom note was altered to include the victim's name, which was also included in the file extension added to encrypted files. BitPaymer's file encryption was updated to use 256-bit AES in lieu of the earlier 128-bit RC4. Researchers suggest the swap was due to "relative weakness" of RC4 compared with AES.

The latest version of BitPaymer has been used in at least 15 confirmed ransomware attacks since November. Activity has continued through 2019, with multiple incidents in June and July.

In June, lookalike DoppelPaymer arrived on the scene. Researchers recovered DoppelPaymer builds dating back to April 2019; however, because these were missing new features seen in later versions, it's likely they may have been test builds. CrowdStrike has confirmed eight malware builds and three victims with ransoms starting at $25,000 and exceeding $1.2 million.

Adversaries typically gain access to targets via other malware like Emotet or Dridex, Meyers explains. Once they identify a target, they begin to interact by escalating privileges, moving laterally, and getting to a position with enough reach to deploy the ransomware payload.

"The code is very similar" to BitPaymer's, says Meyers of DoppelPaymer, adding that "the actor likely had access to the BitPaymer source code and created a forked version where they added some customizations such as changing the cryptography and the ransom note schema."

While DoppelPaymer's ransom note is similar to the one used by the original BitPaymer in 2018, there have been some changes. The payment portal is "almost identical" to the original BitPaymer portal, researchers report, and it contains a ransom amount, countdown timer, and bitcoin address for payment. Both threats use Tor for ransom payment and the .locked extension.

Code overlaps indicate DoppelPaymer is a more recent branch of the latest iteration of BitPaymer, and there are "notable encryption differences" between the two. The actor behind DoppelPaymer made several code changes to improve BitPaymer's functionality: file encryption is now threaded to increase the speed of encrypting files, for example, and DoppelPaymer will run only after a specific command line argument is provided. If no arguments, or an incorrect one, is provided, then DoppelPaymer will crash. It also uses a technique called ProcessHacker, a legitimate open source administrative utility, to terminate some of its processes and services.

Both BitPaymer and DoppelPaymer continue to operate at the same time, as separate threats.

Related Content:

 

Black Hat USA returns to Las Vegas with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions, and service providers in the Business Hall. Click for information on the conference and to register.

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
News
Former CISA Director Chris Krebs Discusses Risk Management & Threat Intel
Kelly Sheridan, Staff Editor, Dark Reading,  2/23/2021
Edge-DRsplash-10-edge-articles
Security + Fraud Protection: Your One-Two Punch Against Cyberattacks
Joshua Goldfarb, Director of Product Management at F5,  2/23/2021
News
Cybercrime Groups More Prolific, Focus on Healthcare in 2020
Robert Lemos, Contributing Writer,  2/22/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Building the SOC of the Future
Building the SOC of the Future
Digital transformation, cloud-focused attacks, and a worldwide pandemic. The past year has changed the way business works and the way security teams operate. There is no going back.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-23347
PUBLISHED: 2021-03-03
The package github.com/argoproj/argo-cd/cmd before 1.7.13, from 1.8.0 and before 1.8.6 are vulnerable to Cross-site Scripting (XSS) the SSO provider connected to Argo CD would have to send back a malicious error message containing JavaScript to the user.
CVE-2021-25315
PUBLISHED: 2021-03-03
A Incorrect Implementation of Authentication Algorithm vulnerability in of SUSE SUSE Linux Enterprise Server 15 SP 3; openSUSE Tumbleweed allows local attackers to execute arbitrary code via salt without the need to specify valid credentials. This issue affects: SUSE SUSE Linux Enterprise Server 15 ...
CVE-2021-27921
PUBLISHED: 2021-03-03
Pillow before 8.1.1 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for a BLP container, and thus an attempted memory allocation can be very large.
CVE-2021-27922
PUBLISHED: 2021-03-03
Pillow before 8.1.1 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICNS container, and thus an attempted memory allocation can be very large.
CVE-2021-27923
PUBLISHED: 2021-03-03
Pillow before 8.1.1 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICO container, and thus an attempted memory allocation can be very large.