logo

BitPaymer/IEncrypt ransomware

ID: f44341bb-b4ec-45c0-bf07-e4427d54f326

STIX ID: report--f44341bb-b4ec-45c0-bf07-e4427d54f326

Threat Score

75/100

Uploaded: 2026-07-30

Published Date: 2026-07-30

Last Modified Date: 2026-08-06

Created by: dogesec

TLP:CLEAR
ADMIRALTY:A1
...
...
This ANSSI report details the BitPaymer (aka IEncrypt/FriedEx) ransomware used in targeted, manually-operated campaigns since 2017, its infection methods (phishing, compromised websites, weak RDP, third-party compromise), TTPs (credential theft, lateral movement, disabling AV, wiping shadow copies), a DoppelPaymer variant emergence, observed impacts (including Scottish hospitals and US municipalities), and practical detection/mitigation guidance such as a Morphisec YARA rule and backup/Active Directory hardening recommendations.