HomeSecurityDoppelPaymer: The new ransomware originating from BitPaymer

DoppelPaymer: The new ransomware originating from BitPaymer

DoublePaymerSome researchers , who specialize in malware ,have discovered a new ransomware, which they have named DoppelPaymer. The DoppelPaymer ransomware has been in use by hackers for about a month. The first victims appeared in mid-June. The hackers encrypted the victims' files and demanded hundreds of thousands of dollars in return.

The ransomware appears in eight variants. The first appeared in April.

The victims come mainly from the public service sector

DoppelPaymer is named after BitPaymer, as much of code is shared. Three victims have reported paying the ransom (ranging from 2 BTC to 100 BTC).

The value of Bitcoin at the end of April was around $5,150 and reached $12,000 in late June and early July.

One of the victims is the town of Edcouch, Texas. The hackers demanded 8 BTC to decrypt the data.

There is not much information about when the attack took place. However, city officials said they paid $40,000. This means the attack likely occurred in early May or earlier, when the value of bitcoin was around $5,500.

Researchers noticed some key similarities between the DoppelPaymer and BitPaymer payment portals. On both pages, at the top there is the title “Bit paymer.” Furthermore, as we mentioned above, the two ransomware have much of their code in common.

DoppelPaymer: The new ransomware originating from BitPaymer

However, they have different encryption schemes.

Examining the differences and similarities between the two ransomware, researchers Brett Stone-Gross, Sergei Frankoff, and Bex Hartley concluded that the new ransomware is likely the work of a member of the team behind BitPaymer who has launched his own ransomware operation.

Both BitPaymer and DoppelPaymer operate in parallel. Victims of both ransomware have been identified in both June and July.

The new ransomware is slightly modified and is superior to BitPaymer , as it uses methods that allow it to encrypt victims' files faster

The group behind BitPaymer is the same one behind the Dridex banking trojan and is known as INDRIK SPIDER.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS