Some researchers , who specialize in malware ,have discovered a new ransomware, which they have named DoppelPaymer. The DoppelPaymer ransomware has been in use by hackers for about a month. The first victims appeared in mid-June. The hackers encrypted the victims' files and demanded hundreds of thousands of dollars in return.
The ransomware appears in eight variants. The first appeared in April.
The victims come mainly from the public service sector
DoppelPaymer is named after BitPaymer, as much of code is shared. Three victims have reported paying the ransom (ranging from 2 BTC to 100 BTC).
The value of Bitcoin at the end of April was around $5,150 and reached $12,000 in late June and early July.
One of the victims is the town of Edcouch, Texas. The hackers demanded 8 BTC to decrypt the data.
There is not much information about when the attack took place. However, city officials said they paid $40,000. This means the attack likely occurred in early May or earlier, when the value of bitcoin was around $5,500.
Researchers noticed some key similarities between the DoppelPaymer and BitPaymer payment portals. On both pages, at the top there is the title “Bit paymer.” Furthermore, as we mentioned above, the two ransomware have much of their code in common.

However, they have different encryption schemes.
Examining the differences and similarities between the two ransomware, researchers Brett Stone-Gross, Sergei Frankoff, and Bex Hartley concluded that the new ransomware is likely the work of a member of the team behind BitPaymer who has launched his own ransomware operation.
Both BitPaymer and DoppelPaymer operate in parallel. Victims of both ransomware have been identified in both June and July.
The new ransomware is slightly modified and is superior to BitPaymer , as it uses methods that allow it to encrypt victims' files faster
The group behind BitPaymer is the same one behind the Dridex banking trojan and is known as INDRIK SPIDER.
