Inactive ransomware operator
← All groupsDoppelpaymer
aka Pay OR Grief, BitPaymer, IEncrypt, FriedEx · 25 victims indexed · first seen 7 years ago · last activity 5 years ago
At a glance
- Status
- inactive
- Aliases
- Pay OR Grief, BitPaymer, IEncrypt, FriedEx
- First seen
- 7 years ago
- Last activity
- 5 years ago
- Onion sites
- 2 known endpoints
- Primary sector
- Government Facilities · 10 hits
About
References
79 linksExternal sources curated by the MISP threat-intel community.
- crowdstrike.com/blog/doppelpaymer-ransomware-and-dridex-2/
- malpedia.caad.fkie.fraunhofer.de/details/win.doppelpaymer
- aithority.com/security/doppelpaymer-ransomware-attack-sinks-a-global-motor-companys-20-million
- zscaler.com/blogs/security-research/doppelpaymer-continues-cause-grief-through-rebranding
- secureworks.com/research/threat-profiles/gold-heron
- apnews.com/article/virus-outbreak-elections-georgia-voting-2020-voting-c191f128b36d1c0334c9d0b173daa18c
- blog.chainalysis.com/reports/ransomware-connections-maze-egregor-suncrypt-doppelpaymer
- cisoclub.ru/doc/otchet-kompanii-group-ib-ransomware-uncovered-2020-2021/?bp-attachment=group-ib_ransomware_uncovered_2020-2021.pdf
- docs.google.com/spreadsheets/d/1MI8Z2tBhmqQ5X8Wf_ozv3dVjz5sJOs-3
- go.crowdstrike.com/rs/281-OBQ-266/images/Report2020CrowdStrikeGlobalThreatReport.pdf
- go.crowdstrike.com/rs/281-OBQ-266/images/Report2021GTR.pdf
- i.blackhat.com/eu-20/Wednesday/eu-20-Clarke-Its-Not-FINished-The-Evolving-Maturity-In-Ransomware-Operations-wp.pdf
- i.blackhat.com/eu-20/Wednesday/eu-20-Clarke-Its-Not-FINished-The-Evolving-Maturity-In-Ransomware-Operations.pdf
- intel471.com/blog/ransomware-attack-access-merchants-infostealer-escrow-service/
- ke-la.com/how-ransomware-gangs-find-new-monetization-schemes-and-evolve-in-marketing/
- ke-la.com/to-attack-or-not-to-attack-targeting-the-healthcare-sector-in-the-underground-ecosystem/
- ke-la.com/zooming-into-darknet-threats-targeting-jp-orgs-kela/
- killingthebear.jorgetesta.tech/actors/evil-corp
- krebsonsecurity.com/2021/08/ransomware-gangs-and-the-name-game-distraction/
- lifars.com/wp-content/uploads/2022/01/GriefRansomware_Whitepaper-2.pdf
Timeline
13 monthsTop countries
Top sectors
MITRE ATT&CK
10 techniques · 9 tacticsTactics
Techniques
Detection · YARA rules
1 rulebitpaymer_ransomware
YARA rule from ATR/Trellix: ransomware/RANSOM_Bitpaymer.yar
source: ATR/Trellix
Recent victims
Loading…
Onion infrastructure
2 known- http://hpoo4dosa3x4ognfxpqcrjwnsigvslm7kv6hvmhh2yqczaxy3j6qnwad.onion
- http://hpoo4dosa3x4ognfxpqcrjwnsigvslm7kv6hvmhh2yqczaxy3j6qnwad.onion/
Source
Updated 5 years agoData on this page is sourced from the group's own leak posts, cross-checked with public ransomware trackers (RansomLook, ransomware.live, RansomWatch), MITRE ATT&CK, and our own Tor and Telegram crawlers. This is a public observatory page — share freely.
